QID 670919
QID 670919: EulerOS Security Update for libplist (EulerOS-SA-2021-2399)
libplist is a library for manipulating Apple Binary and XML Property Lists
Security Fix(es):
The base64decode function in base64.c in libimobiledevice libplist through 1.12 allows attackers to obtain sensitive information from process memory or cause a denial of service (buffer over-read) via split encoded Apple Property List data.(CVE-2017-5209)
The parse_data_node function in bplist.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (memory allocation error) via a crafted plist file.(CVE-2017-6440)
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
An arbitrary attacker may exploit this vulnerability to compromise the system.
CVEs related to QID 670919
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| EulerOS-SA-2021-2399 | EulerOS V2.0SP2 |
|