PT-2017-16572 · Apple+2 · Libplist+2
Zhunkio
·
Publicado
2017-01-21
·
Atualizado
2020-04-02
·
CVE-2017-5545
CVSS v3.1
9.1
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
libplist versions prior to 1.12
Description
The issue allows attackers to obtain sensitive information from process memory or cause a denial of service via Apple Property List data that is too short. This is due to a buffer over-read in the main function in plistutil.c.
Recommendations
For versions prior to 1.12, update to version 1.12 or later to resolve the issue. As a temporary workaround, consider restricting the use of Apple Property List data to minimize the risk of exploitation.
Correção
DoS
Out of bounds Read
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Suse
Libplist