Libimobiledevice · Libimobiledevice/Libplist · CVE-2017-7982
**Name of the Vulnerable Software and Affected Versions**
libimobiledevice/libplist versions prior to 2017-04-19
**Description**
The issue is related to an integer overflow in the `plist from bin` function in `bplist.c`, which allows remote attackers to cause a denial of service, resulting in a heap-based buffer over-read and application crash, via a crafted plist file.
**Recommendations**
For versions prior to 2017-04-19, update to a version released after 2017-04-19 to resolve the issue. As a temporary workaround, consider restricting the use of crafted plist files to minimize the risk of exploitation.