CVE-2017-5834

Name
CVE-2017-5834
Description
The parse_dict_node function in bplist.c in libplist allows attackers to cause a denial of service (out-of-bounds heap read and crash) via a crafted file.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Mailing List http://www.openwall.com/lists/oss-security/2017/01/31/6
Mailing List http://www.openwall.com/lists/oss-security/2017/02/02/4
cve@mitre.org http://www.securityfocus.com/bid/96022
Issue Tracking https://github.com/libimobiledevice/libplist/issues/89
cve@mitre.org https://lists.debian.org/debian-lts-announce/2020/04/msg00002.html

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:libimobiledevice:libplist:*:*:*:*:*:*:*:* libplist == None == None

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
libplist edge-community 2.7.0-r1 Krassy Boykinov <kboykinov@teamcentrixx.com> possibly vulnerable
libplist edge-community 2.7.0-r0 Krassy Boykinov <kboykinov@teamcentrixx.com> possibly vulnerable
libplist edge-community 2.6.0-r1 Krassy Boykinov <kboykinov@teamcentrixx.com> possibly vulnerable
libplist 3.23-community 2.7.0-r0 Krassy Boykinov <kboykinov@teamcentrixx.com> possibly vulnerable