6.4
CVSSv2

CVE-2017-5545

Published: 21/01/2017 Updated: 02/04/2020
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.1 | Impact Score: 5.2 | Exploitability Score: 3.9
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:P

Vulnerability Summary

The main function in plistutil.c in libimobiledevice libplist up to and including 1.12 allows malicious users to obtain sensitive information from process memory or cause a denial of service (buffer over-read) via Apple Property List data that is too short.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

libimobiledevice libplist

Vendor Advisories

Debian Bug report logs - #852385 libplist: CVE-2017-5545 Package: src:libplist; Maintainer for src:libplist is gtkpod Maintainers <pkg-gtkpod-devel@alioth-listsdebiannet>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 24 Jan 2017 05:48:02 UTC Severity: grave Tags: fixed-upstream, patch, security, ...
Debian Bug report logs - #851196 libplist: CVE-2017-5209 Package: src:libplist; Maintainer for src:libplist is gtkpod Maintainers <pkg-gtkpod-devel@alioth-listsdebiannet>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 12 Jan 2017 21:15:01 UTC Severity: grave Tags: fixed-upstream, patch, security, ...
Debian Bug report logs - #854000 CVE-2017-5834 CVE-2017-5835 CVE-2017-5836 Package: src:libplist; Maintainer for src:libplist is gtkpod Maintainers <pkg-gtkpod-devel@alioth-listsdebiannet>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Thu, 2 Feb 2017 22:21:02 UTC Severity: grave Tags: security, upstream ...
The main function in plistutilc in libimobiledevice libplist through 112 allows attackers to obtain sensitive information from process memory or cause a denial of service (buffer over-read) via Apple Property List data that is too short ...
The main function in plistutilc in libimobiledevice libplist through 112 allows attackers to obtain sensitive information from process memory or cause a denial of service (buffer over-read) via Apple Property List data that is too short ...