Related Vulnerabilities: CVE-2017-5545  

The main function in plistutil.c in libimobiledevice libplist through 1.12 allows attackers to obtain sensitive information from process memory or cause a denial of service (buffer over-read) via Apple Property List data that is too short.

Severity Medium

Remote No

Type Denial of service

Description

The main function in plistutil.c in libimobiledevice libplist through 1.12 allows attackers to obtain sensitive information from process memory or cause a denial of service (buffer over-read) via Apple Property List data that is too short.

AVG-215 libplist 1.12-6 2.0.0-1 High Fixed

16 May 2017 ASA-201705-18 AVG-215 libplist High multiple issues

https://bugzilla.redhat.com/show_bug.cgi?id=1416002