Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-6437

Опубликовано: 24 фев. 2017
Источник: redhat
CVSS3: 3.3
EPSS Низкий

Описание

The base64encode function in base64.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (out-of-bounds read) via a crafted plist file.

An out-of-bounds read flaw was found in libplist. A specially crafted plist file could be used by an attacker to crash the application using libplist.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libplistWill not fix
Red Hat Enterprise Linux 7libplistWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1432954libplist: Out-of-bounds heap read in base64encode function

EPSS

Процентиль: 32%
0.00123
Низкий

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 5
ubuntu
почти 9 лет назад

The base64encode function in base64.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (out-of-bounds read) via a crafted plist file.

CVSS3: 5
nvd
почти 9 лет назад

The base64encode function in base64.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (out-of-bounds read) via a crafted plist file.

CVSS3: 5
debian
почти 9 лет назад

The base64encode function in base64.c in libimobiledevice libplist 1.1 ...

CVSS3: 5
github
больше 3 лет назад

The base64encode function in base64.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (out-of-bounds read) via a crafted plist file.

suse-cvrf
больше 8 лет назад

Security update for libplist

EPSS

Процентиль: 32%
0.00123
Низкий

3.3 Low

CVSS3