1.9
CVSSv2

CVE-2017-6437

Published: 15/03/2017 Updated: 04/04/2017
CVSS v2 Base Score: 1.9 | Impact Score: 2.9 | Exploitability Score: 3.4
CVSS v3 Base Score: 5 | Impact Score: 3.6 | Exploitability Score: 1.3
VMScore: 169
Vector: AV:L/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

The base64encode function in base64.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (out-of-bounds read) via a crafted plist file.

Vulnerable Product Search on Vulmon Subscribe to Product

libplist project libplist 1.12

Vendor Advisories

Debian Bug report logs - #858786 libplist: CVE-2017-6438 Package: src:libplist; Maintainer for src:libplist is gtkpod Maintainers <pkg-gtkpod-devel@alioth-listsdebiannet>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 26 Mar 2017 19:39:01 UTC Severity: important Tags: fixed-upstream, patch, secur ...
Debian Bug report logs - #858055 libplist: CVE-2017-6440: Memory allocation error in parse_data_node Package: src:libplist; Maintainer for src:libplist is gtkpod Maintainers <pkg-gtkpod-devel@alioth-listsdebiannet>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 17 Mar 2017 19:33:05 UTC Severity: ...
Debian Bug report logs - #858787 libplist: CVE-2017-6437 Package: src:libplist; Maintainer for src:libplist is gtkpod Maintainers <pkg-gtkpod-devel@alioth-listsdebiannet>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 26 Mar 2017 19:39:04 UTC Severity: important Tags: fixed-upstream, patch Found ...
An out-of-bounds read flaw was found in libplist A specially crafted plist file could be used by an attacker to crash the application using libplist ...
The base64encode function in base64c in libimobiledevice libplist 112 allows local users to cause a denial of service (out-of-bounds read) via a crafted plist file ...