PT-2023-10261 · Libplist+2 · Libplist+2
CVE-2015-10082
·
Publicado
2017-05-01
·
Atualizado
2024-05-17
CVSS v2.0
5.2
Média
| Vetor | AV:A/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
libplist version 1.12
Description
A problematic issue has been found in the XML Handler component of libplist, specifically affecting the
plist from xml function in the src/xplist.c file. This issue leads to an xml external entity reference.Recommendations
To fix this issue, apply the patch named c086cb139af7c82845f6d565e636073ff4b37440. As a temporary workaround, consider restricting the use of the
plist from xml function in the XML Handler component until the patch is applied.Correção
XXE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Suse
Libplist