1.9
CVSSv2

CVE-2017-6439

Published: 15/03/2017 Updated: 04/04/2017
CVSS v2 Base Score: 1.9 | Impact Score: 2.9 | Exploitability Score: 3.4
CVSS v3 Base Score: 5 | Impact Score: 3.6 | Exploitability Score: 1.3
VMScore: 169
Vector: AV:L/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

Heap-based buffer overflow in the parse_string_node function in bplist.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (out-of-bounds write) via a crafted plist file.

Vulnerable Product Search on Vulmon Subscribe to Product

libplist project libplist 1.12

Vendor Advisories

Heap-based buffer overflow in the parse_string_node function in bplistc in libimobiledevice libplist 112 allows local users to cause a denial of service (out-of-bounds write) via a crafted plist file ...
Heap-based buffer overflow in the parse_string_node function in bplistc in libimobiledevice libplist 112 allows local users to cause a denial of service (out-of-bounds write) via a crafted plist file ...