PT-2023-10261 · Libplist+2 · Libplist+2

Published

2017-05-01

·

Updated

2024-05-17

·

CVE-2015-10082

CVSS v2.0

5.2

Medium

VectorAV:A/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions libplist version 1.12
Description A problematic issue has been found in the XML Handler component of libplist, specifically affecting the plist from xml function in the src/xplist.c file. This issue leads to an xml external entity reference.
Recommendations To fix this issue, apply the patch named c086cb139af7c82845f6d565e636073ff4b37440. As a temporary workaround, consider restricting the use of the plist from xml function in the XML Handler component until the patch is applied.

Fix

XXE

Weakness Enumeration

Related Identifiers

ALT-PU-2017-1551
CVE-2015-10082
SUSE-SU-2023:0872-1
SUSE-SU-2023_0872-1

Affected Products

Alt Linux
Suse
Libplist