Описание
Security update for libplist
This update for libplist fixes the following issues:
Security issues fixed:
- CVE-2017-6439: Heap-based buffer overflow in the parse_string_node function. (bsc#1029638)
- CVE-2017-6438: Heap-based buffer overflow in the parse_unicode_node function. (bsc#1029706)
- CVE-2017-6437: The base64encode function in base64.c allows local users to cause denial of service (out-of-bounds read) via a crafted plist file. (bsc#1029707)
- CVE-2017-6436: Integer overflow in parse_string_node. (bsc#1029751)
- CVE-2017-6435: Crafted plist file could lead to Heap-buffer overflow. (bsc#1029639)
Список пакетов
SUSE Linux Enterprise Desktop 12 SP2
SUSE Linux Enterprise Desktop 12 SP3
SUSE Linux Enterprise Server 12 SP2
SUSE Linux Enterprise Server 12 SP3
SUSE Linux Enterprise Server for Raspberry Pi 12 SP2
SUSE Linux Enterprise Server for SAP Applications 12 SP2
SUSE Linux Enterprise Server for SAP Applications 12 SP3
SUSE Linux Enterprise Software Development Kit 12 SP2
SUSE Linux Enterprise Software Development Kit 12 SP3
SUSE Linux Enterprise Workstation Extension 12 SP2
SUSE Linux Enterprise Workstation Extension 12 SP3
Ссылки
- Link for SUSE-SU-2017:2201-1
- E-Mail link for SUSE-SU-2017:2201-1
- SUSE Security Ratings
- SUSE Bug 1029638
- SUSE Bug 1029639
- SUSE Bug 1029706
- SUSE Bug 1029707
- SUSE Bug 1029751
- SUSE CVE CVE-2017-6435 page
- SUSE CVE CVE-2017-6436 page
- SUSE CVE CVE-2017-6437 page
- SUSE CVE CVE-2017-6438 page
- SUSE CVE CVE-2017-6439 page
Описание
The parse_string_node function in bplist.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (memory corruption) via a crafted plist file.
Затронутые продукты
Ссылки
- CVE-2017-6435
- SUSE Bug 1029639
Описание
The parse_string_node function in bplist.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (memory allocation error) via a crafted plist file.
Затронутые продукты
Ссылки
- CVE-2017-6436
- SUSE Bug 1029751
Описание
The base64encode function in base64.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (out-of-bounds read) via a crafted plist file.
Затронутые продукты
Ссылки
- CVE-2017-6437
- SUSE Bug 1029707
Описание
Heap-based buffer overflow in the parse_unicode_node function in bplist.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (out-of-bounds write) and possibly code execution via a crafted plist file.
Затронутые продукты
Ссылки
- CVE-2017-6438
- SUSE Bug 1029706
Описание
Heap-based buffer overflow in the parse_string_node function in bplist.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (out-of-bounds write) via a crafted plist file.
Затронутые продукты
Ссылки
- CVE-2017-6439
- SUSE Bug 1029638