PT-2017-18044 · Libimobiledevice+3 · Libimobiledevice/Libplist+3

Zhunkio

·

Publicado

2017-04-20

·

Atualizado

2020-04-02

·

CVE-2017-7982

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions libimobiledevice/libplist versions prior to 2017-04-19
Description The issue is related to an integer overflow in the plist from bin function in bplist.c, which allows remote attackers to cause a denial of service, resulting in a heap-based buffer over-read and application crash, via a crafted plist file.
Recommendations For versions prior to 2017-04-19, update to a version released after 2017-04-19 to resolve the issue. As a temporary workaround, consider restricting the use of crafted plist files to minimize the risk of exploitation.

Correção

DoS

Integer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2017-1551
CVE-2017-7982
DLA-2168-1
MGASA-2018-0025
SUSE-SU-2017:1368-1
SUSE-SU-2017:1379-1
USN-3429-1

Produtos afetados

Alt Linux
Suse
Ubuntu
Libimobiledevice/Libplist