CVE-2017-5836
03.03.2017, 15:59
The plist_free_data function in plist.c in libplist allows attackers to cause a denial of service (crash) via vectors involving an integer node that is treated as a PLIST_KEY and then triggers an invalid free.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| libimobiledevice | libplist | * |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libplist |
|
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libplist++-devel |
| ||||||||||||||||||||||||||||||||||||||||||||||||
| libplist++3 |
| ||||||||||||||||||||||||||||||||||||||||||||||||
| libplist-2_0-3 |
| ||||||||||||||||||||||||||||||||||||||||||||||||
| libplist-2_0-devel |
| ||||||||||||||||||||||||||||||||||||||||||||||||
| libplist-devel |
| ||||||||||||||||||||||||||||||||||||||||||||||||
| libplist3 |
|
Common Weakness Enumeration
References