Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-5545

Опубликовано: 17 янв. 2017
Источник: redhat
CVSS3: 4.4
EPSS Низкий

Описание

The main function in plistutil.c in libimobiledevice libplist through 1.12 allows attackers to obtain sensitive information from process memory or cause a denial of service (buffer over-read) via Apple Property List data that is too short.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libplistWill not fix
Red Hat Enterprise Linux 7libplistWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1416002libplist: Out-of-bounds heap buffer read in plistutil

EPSS

Процентиль: 61%
0.00416
Низкий

4.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.1
ubuntu
около 9 лет назад

The main function in plistutil.c in libimobiledevice libplist through 1.12 allows attackers to obtain sensitive information from process memory or cause a denial of service (buffer over-read) via Apple Property List data that is too short.

CVSS3: 9.1
nvd
около 9 лет назад

The main function in plistutil.c in libimobiledevice libplist through 1.12 allows attackers to obtain sensitive information from process memory or cause a denial of service (buffer over-read) via Apple Property List data that is too short.

CVSS3: 9.1
debian
около 9 лет назад

The main function in plistutil.c in libimobiledevice libplist through ...

CVSS3: 9.1
github
больше 3 лет назад

The main function in plistutil.c in libimobiledevice libplist through 1.12 allows attackers to obtain sensitive information from process memory or cause a denial of service (buffer over-read) via Apple Property List data that is too short.

suse-cvrf
почти 9 лет назад

Security update for libplist

EPSS

Процентиль: 61%
0.00416
Низкий

4.4 Medium

CVSS3