Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
libplist is a library for reading and writing the Apple binary and XML property lists format. It's part of the libimobiledevice stack, providing access to iDevices (iPod, iPhone, iPad ...). . Package : libplist Version : 1.11-3+deb8u1 CVE ID : CVE-2017-5209 CVE-2017-5545 CVE-2017-5834 CVE-2017-5835 CVE-2017-6435 CVE-2017-6436 CVE-2017-6439 CVE-2017-7982 Debian Bug : 851196 852385 854000 860945 libplist is a library for reading and writing the Apple binary and XML property lists format. It's part of the libimobiledevice stack, providing access to iDevices (iPod, iPhone, iPad ...). CVE-2017-5209 The base64decode function in base64.c allows attackers to obtain sensitive information from process memory or cause a denial of service (buffer over-read) via split encoded Apple Property List data. CVE-2017-5545 The main function in plistutil.c allows attackers to obtain sensitive information from process memory or cause a denial of service (buffer over-read) via Apple Property List data that is too short. CVE-2017-5834 The parse_dict_node function in bplist.c allows attackers to cause a denial of service (out-of-bounds heap read and crash) via a crafted file. CVE-2017-5835 libplist allows attackers to cause a denial of service (large memory allocation and crash) via vectors involving an offset size of zero. CVE-2017-6435 The parse_string_node function in bplist.c allows local users to cause a denial of service (memory corruption) via a crafted plist file. CVE-2017-6436 The parse_string_node function in bplist.c allows local users to cause a denial of service (memory allocation error) via a crafted plist file. CVE-2017-6439 Heap-based buffer overflow in the parse_string_node function in bplist.c allows local users to cause a denial of service (out-of-bounds write) via a crafted plist file. CVE-2017-7982 Integer overflow in the plist_from_bin function in bplist.c allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted plist file. For Debian 8 "Jessie", these problems have been fixed in version 1.11-3+deb8u1. We recommend that you upgrade your libplist packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Enhance libplist to version 1.11-3+deb8u1 to mitigate several security vulnerabilities and safeguard against data leaks.. libplist security, debian advisory, memory corruption, DoS, info disclosure. . Severity: Critical. LinuxSecurity.com Team
New libplist packages are available for Slackware 14.2 and -current to fix security issues. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] libplist (SSA:2017-320-01) New libplist packages are available for Slackware 14.2 and -current to fix security issues. Here are the details from the Slackware 14.2 ChangeLog: +--------------------------+ patches/packages/libplist-2.0.0-i586-1_slack14.2.txz: Upgraded. This update fixes several security issues. For more information, see: https://www.cve.org/CVERecord?id=CVE-2017-6440 https://www.cve.org/CVERecord?id=CVE-2017-6439 https://www.cve.org/CVERecord?id=CVE-2017-6438 https://www.cve.org/CVERecord?id=CVE-2017-6437 https://www.cve.org/CVERecord?id=CVE-2017-6436 https://www.cve.org/CVERecord?id=CVE-2017-6435 https://www.cve.org/CVERecord?id=CVE-2017-5836 https://www.cve.org/CVERecord?id=CVE-2017-5835 https://www.cve.org/CVERecord?id=CVE-2017-5834 https://www.cve.org/CVERecord?id=CVE-2017-5545 https://www.cve.org/CVERecord?id=CVE-2017-5209 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 14.2: ftp://ftp.slackware.com/pub/slackware/slackware-14.2/patches/packages/libplist-2.0.0-i586-1_slack14.2.txz Updated package for Slackware x86_64 14.2: ftp://ftp.slackware.com/pub/slackware/slackware64-14.2/patches/packages/libplist-2.0.0-x86_64-1_slack14.2.txz Updated package for Slackware -current: Updated package for Slackware x86_64 -current: MD5 signatures: +-------------+ Slackware 14.2 package: 3e2f07b94d23021ef78c81ec8ca10148 libplist-2.0.0-i586-1_slack14.2.txz Slackware x86_64 14.2 package: 17e0490072a2374726f4311244f1d1c9 libplist-2.0.0-x86_64-1_slack14.2.txz Slackware -current package: bdf0b49378aa70133e740b9c4797e050 l/libplist-2.0.0-i586-1.txz Slackware x86_64 -current package: e5ac1fa583f9a9e2710c41d90c1100dd l/libplist-2.0.0-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg libplist-2.0.0-i586-1_slack14.2.txz +-----+ . Updated libplist modules for Slackware 14.2 and -current resolve multiple vulnerabilities, keeping your environment protected.. libplist packages, slackware upgrade, security patch. . LinuxSecurity.com Team
Libplist could be made to crash if it opened a specially craftedfile.. =========================================================================Ubuntu Security Notice USN-3429-1 September 25, 2017 libplist vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 17.04 - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Libplist could be made to crash if it opened a specially crafted file. Software Description: - libplist: Library for handling Apple binary and XML property lists Details: Wang Junjie discovered that Libplist incorrectly handled certain files. If a user were tricked into opening a crafted file, an attacker could possibly use this to cause a crash or denial or service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 17.04: libplist-utils 1.12-3.1ubuntu0.17.04.1 libplist3 1.12-3.1ubuntu0.17.04.1 python-plist 1.12-3.1ubuntu0.17.04.1 Ubuntu 16.04 LTS: libplist-utils 1.12-3.1ubuntu0.16.04.1 libplist3 1.12-3.1ubuntu0.16.04.1 python-plist 1.12-3.1ubuntu0.16.04.1 Ubuntu 14.04 LTS: libplist-utils 1.10-1ubuntu0.1 libplist1 1.10-1ubuntu0.1 python-plist 1.10-1ubuntu0.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-3429-1 CVE-2017-7982 Package Information: https://launchpad.net/ubuntu/+source/libplist/1.12-3.1ubuntu0.17.04.1 https://launchpad.net/ubuntu/+source/libplist/1.12-3.1ubuntu0.16.04.1 https://launchpad.net/ubuntu/+source/libplist/1.10-1ubuntu0.1 . Keep your Ubuntu installations secure by applying the necessary updates to resolve the libplist vulnerability impacting several versions. Discover further details here.. libplist vulnerability, Denial Of Service, Ubuntu Updates. . Severity: Critical. LinuxSecurity.com Team
The package libplist before version 2.0.0-1 is vulnerable to multiple issues including arbitrary command execution, denial of service and information disclosure. . Arch Linux Security Advisory ASA-201705-18 ========================================= Severity: High Date : 2017-05-16 CVE-ID : CVE-2017-5209 CVE-2017-5545 CVE-2017-5834 CVE-2017-5835 CVE-2017-5836 CVE-2017-6435 CVE-2017-6436 CVE-2017-6437 CVE-2017-6438 CVE-2017-6439 CVE-2017-6440 Package : libplist Type : multiple issues Remote : Yes Link : https://security.archlinux.org/AVG-215 Summary ====== The package libplist before version 2.0.0-1 is vulnerable to multiple issues including arbitrary command execution, denial of service and information disclosure. Resolution ========= Upgrade to 2.0.0-1. # pacman -Syu "libplist> =2.0.0-1" The problems have been fixed upstream in version 2.0.0. Workaround ========= None. Description ========== - CVE-2017-5209 (information disclosure) The base64decode function in base64.c in libimobiledevice libplist through 1.12 allows attackers to obtain sensitive information from process memory or cause a denial of service (buffer over-read) via split encoded Apple Property List data. - CVE-2017-5545 (denial of service) The main function in plistutil.c in libimobiledevice libplist through 1.12 allows attackers to obtain sensitive information from process memory or cause a denial of service (buffer over-read) via Apple Property List data that is too short. - CVE-2017-5834 (denial of service) The parse_dict_node function in bplist.c in libplist allows attackersto cause a denial of service (out-of-bounds heap read and crash) via a crafted file. - CVE-2017-5835 (denial of service) libplist allows attackers to cause a denial of service (large memory allocation and crash) via vectors involving an offset size of zero. - CVE-2017-5836 (denial of service) The plist_free_data function in plist.c in libplist allows attackers to cause a denial of service (crash) via vectors involving aninteger node that is treated as a PLIST_KEY and then triggers an invalid free. - CVE-2017-6435 (denial of service) The parse_string_node function in bplist.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (memory corruption) via a crafted plist file. - CVE-2017-6436 (denial of service) The parse_string_node function in bplist.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (memory allocation error) via a crafted plist file. - CVE-2017-6437 (denial of service) The base64encode function in base64.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (out-of-bounds read) via a crafted plist file. - CVE-2017-6438 (arbitrary command execution) Heap-based buffer overflow in the parse_unicode_node function in bplist.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (out-of-bounds write) and possibly code execution via a crafted plist file. - CVE-2017-6439 (denial of service) Heap-based buffer overflow in the parse_string_node function in bplist.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (out-of-bounds write) via a crafted plist file. - CVE-2017-6440 (denial of service) The parse_data_node function in bplist.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (memory allocation error) via a crafted plist file. Impact ===== An attacker is able to crash the process, read sensitive information or execute arbitrary code on the host by providing a crafted plist fileor string. References ========= https://github.com/libimobiledevice/libplist/issues/93 https://github.com/libimobiledevice/libplist/issues/94 https://github.com/libimobiledevice/libplist/issues/95 https://github.com/libimobiledevice/libplist/issues/99 https://github.com/libimobiledevice/libplist/issues/98 https://github.com/libimobiledevice/libplist/issues/100 https://github.com/libimobiledevice/libplist/blob/master/NEWS https://bugzilla.redhat.com/show_bug.cgi?id=1412613 https://bugzilla.redhat.com/show_bug.cgi?id=1416002 https://bugzilla.redhat.com/show_bug.cgi?id=1418591 https://bugzilla.redhat.com/show_bug.cgi?id=1418592 https://bugzilla.redhat.com/show_bug.cgi?id=1418593 https://security.archlinux.org/CVE-2017-5209 https://security.archlinux.org/CVE-2017-5545 https://security.archlinux.org/CVE-2017-5834 https://security.archlinux.org/CVE-2017-5835 https://security.archlinux.org/CVE-2017-5836 https://security.archlinux.org/CVE-2017-6435 https://security.archlinux.org/CVE-2017-6436 https://security.archlinux.org/CVE-2017-6437 https://security.archlinux.org/CVE-2017-6438 https://security.archlinux.org/CVE-2017-6439 https://security.archlinux.org/CVE-2017-6440 . The Arch Linux Security Notice ASA-202305-11 points out significant flaws in libxml2 requiring immediate rectification.. libplist issues, Arch Linux advisory, command risks. . LinuxSecurity.com Team
Version 2.0.0 Changes: * New light-weight custom XML parser * Remove libxml2 dependency * Refactor binary plist parsing * Improved malformed XML and binary plist detection and error handling * Add parser debug/error output (when compiled with --enable-debug), controlled via environment variables * Fix unicode character handling * Add PLIST_IS_* helper macros for the. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-3849af4477 2017-05-12 14:08:49.129401 --------------------------------------------------------------------------------Name : libplist Product : Fedora 24 Version : 2.0.0 Release : 1.fc24 URL : https://libimobiledevice.org/ Summary : Library for manipulating Apple Binary and XML Property Lists Description : libplist is a library for manipulating Apple Binary and XML Property Lists --------------------------------------------------------------------------------Update Information: Version 2.0.0 Changes: * New light-weight custom XML parser * Remove libxml2 dependency * Refactor binary plist parsing * Improved malformed XML and binary plist detection and error handling * Add parser debug/error output (when compiled with --enable-debug), controlled via environment variables * Fix unicode character handling * Add PLIST_IS_* helper macros for the different node types * Extend date/time range and date conversion issues * Add plist_is_binary() and plist_from_memory() functions to the interface * Plug several memory leaks * Speed improvements for handling large plist files Includes security fixes for: * CVE-2017-6440 * CVE-2017-6439 * CVE-2017-6438 * CVE-2017-6437 * CVE-2017-6436 * CVE-2017-6435 * CVE-2017-5836 * CVE-2017-5835 * CVE-2017-5834 * CVE-2017-5545 * CVE-2017-5209 ... and several others that didn't receive any CVE (yet). --------------------------------------------------------------------------------References: [1 ] Bug #1432965 - CVE-2017-6440 libplist: Memory allocation error in parse_data_node https://bugzilla.redhat.com/show_bug.cgi?id=1432965 [ 2 ] Bug #1432959 - CVE-2017-6439 libplist: Heap-based buffer overflow in parse_string_node https://bugzilla.redhat.com/show_bug.cgi?id=1432959 [ 3 ] Bug #1432956 - CVE-2017-6438 libplist: Heap-based buffer overflow in parse_unicode_node https://bugzilla.redhat.com/show_bug.cgi?id=1432956 [ 4 ] Bug #1432954 - CVE-2017-6437 libplist: Out-of-bounds heap read in base64encode function https://bugzilla.redhat.com/show_bug.cgi?id=1432954 [ 5 ] Bug #1432951 - CVE-2017-6436 libplist: Integer overflow in parse_string_node https://bugzilla.redhat.com/show_bug.cgi?id=1432951 [ 6 ] Bug #1412613 - CVE-2017-5209 libplist: base64decode buffer over-read via split encoded Apple Property List data https://bugzilla.redhat.com/show_bug.cgi?id=1412613 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade libplist' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Version 2.0.0 Changes: * New light-weight custom XML parser * Remove libxml2 dependency * Refactor binary plist parsing * Improved malformed XML and binary plist detection and error handling * Add parser debug/error output (when compiled with --enable-debug), controlled via environment variables * Fix unicode character handling * Add PLIST_IS_* helper macros for the. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-4047180cd3 2017-05-12 04:05:28.496941 --------------------------------------------------------------------------------Name : libplist Product : Fedora 25 Version : 2.0.0 Release : 1.fc25 URL : https://libimobiledevice.org/ Summary : Library for manipulating Apple Binary and XML Property Lists Description : libplist is a library for manipulating Apple Binary and XML Property Lists --------------------------------------------------------------------------------Update Information: Version 2.0.0 Changes: * New light-weight custom XML parser * Remove libxml2 dependency * Refactor binary plist parsing * Improved malformed XML and binary plist detection and error handling * Add parser debug/error output (when compiled with --enable-debug), controlled via environment variables * Fix unicode character handling * Add PLIST_IS_* helper macros for the different node types * Extend date/time range and date conversion issues * Add plist_is_binary() and plist_from_memory() functions to the interface * Plug several memory leaks * Speed improvements for handling large plist files Includes security fixes for: * CVE-2017-6440 * CVE-2017-6439 * CVE-2017-6438 * CVE-2017-6437 * CVE-2017-6436 * CVE-2017-6435 * CVE-2017-5836 * CVE-2017-5835 * CVE-2017-5834 * CVE-2017-5545 * CVE-2017-5209 ... and several others that didn't receive any CVE (yet). --------------------------------------------------------------------------------References: [1 ] Bug #1432965 - CVE-2017-6440 libplist: Memory allocation error in parse_data_node https://bugzilla.redhat.com/show_bug.cgi?id=1432965 [ 2 ] Bug #1432959 - CVE-2017-6439 libplist: Heap-based buffer overflow in parse_string_node https://bugzilla.redhat.com/show_bug.cgi?id=1432959 [ 3 ] Bug #1432956 - CVE-2017-6438 libplist: Heap-based buffer overflow in parse_unicode_node https://bugzilla.redhat.com/show_bug.cgi?id=1432956 [ 4 ] Bug #1432954 - CVE-2017-6437 libplist: Out-of-bounds heap read in base64encode function https://bugzilla.redhat.com/show_bug.cgi?id=1432954 [ 5 ] Bug #1432951 - CVE-2017-6436 libplist: Integer overflow in parse_string_node https://bugzilla.redhat.com/show_bug.cgi?id=1432951 [ 6 ] Bug #1412613 - CVE-2017-5209 libplist: base64decode buffer over-read via split encoded Apple Property List data https://bugzilla.redhat.com/show_bug.cgi?id=1412613 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade libplist' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
- Update to upstream 2.0.0 - Fixes the following CVEs plus others - CVE-2017-6440 CVE-2017-6439 CVE-2017-6438 CVE-2017-6437 CVE-2017-6436 CVE-2017-6435 CVE-2017-5836 CVE-2017-5835 CVE-2017-5834 CVE-2017-5545 CVE-2017-5209. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-d8173aacff 2017-05-02 15:56:05.733668 --------------------------------------------------------------------------------Name : libplist Product : Fedora 26 Version : 2.0.0 Release : 1.fc26 URL : https://libimobiledevice.org/ Summary : Library for manipulating Apple Binary and XML Property Lists Description : libplist is a library for manipulating Apple Binary and XML Property Lists --------------------------------------------------------------------------------Update Information: - Update to upstream 2.0.0 - Fixes the following CVEs plus others -CVE-2017-6440 CVE-2017-6439 CVE-2017-6438 CVE-2017-6437 CVE-2017-6436 CVE-2017-6435 CVE-2017-5836 CVE-2017-5835 CVE-2017-5834 CVE-2017-5545 CVE-2017-5209 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade libplist' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.