Alerts This Week
Warning Icon 1 1,109
Alerts This Week
Warning Icon 1 1,109

Debian Jessie: DLA-2168-1 Critical: libplist Memory Issues

debian lts
Calendar Grey April 2, 2020
Dist Debian Esm H88
Enhance libplist to version 1.11-3+deb8u1 to mitigate several security vulnerabilities and safeguard against data leaks.
libplist is a library for reading and writing the Apple binary and XML property lists format

Summary

CVE-2017-5209

The base64decode function in base64.c allows attackers to obtain sensitive
information from process memory or cause a denial of service (buffer
over-read) via split encoded Apple Property List data.

CVE-2017-5545

The main function in plistutil.c allows attackers to obtain sensitive
information from process memory or cause a denial of service (buffer
over-read) via Apple Property List data that is too short.

CVE-2017-5834

The parse_dict_node function in bplist.c allows attackers to cause a denial
of service (out-of-bounds heap read and crash) via a crafted file.

CVE-2017-5835

libplist allows attackers to cause a denial of service (large memory
allocation and crash) via vectors involving an offset size of zero.

CVE-2017-6435

The parse_string_node function in bplist.c allows local users to cause a
denial of service (memory corruption) via a crafted plist file.

CVE-2017-6436

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: libplist
Version: 1.11-3+deb8u1
CVE ID: CVE-2017-5209 CVE-2017-5545 CVE-2017-5834 CVE-2017-5835
Debian Bug: 851196 852385 854000 860945

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here