CVE-2017-5545
Summary
| CVE | CVE-2017-5545 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-01-21 01:59:00 UTC |
| Updated | 2020-04-02 10:15:00 UTC |
| Description | The main function in plistutil.c in libimobiledevice libplist through 1.12 allows attackers to obtain sensitive information from process memory or cause a denial of service (buffer over-read) via Apple Property List data that is too short. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Libimobiledevice Libplist 'plistutil.c' Heap Buffer Overflow Vulnerability |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| [SECURITY] [DLA 2168-1] libplist security update |
MLIST |
lists.debian.org |
|
| AddressSanitizer: heap-buffer-overflow on address 0xb5e007d7 at pc 0x804a78c bp 0xbf815888 sp 0xbf81587c · Issue #87 · libimobiledevice/libplist · GitHub |
CONFIRM |
github.com |
Issue Tracking, Patch, Third Party Advisory |
| plistutil: Prevent OOB heap buffer read by checking input size · libimobiledevice/libplist@7391a50 · GitHub |
CONFIRM |
github.com |
Issue Tracking, Patch, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 671068 EulerOS Security Update for libplist (EulerOS-SA-2019-2613)