First published: Fri Mar 03 2017(Updated: )
The parse_dict_node function in bplist.c in libplist allows attackers to cause a denial of service (out-of-bounds heap read and crash) via a crafted file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
libimobiledevice and libplist |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-5834 is categorized as a denial of service vulnerability due to an out-of-bounds heap read leading to a crash.
To fix CVE-2017-5834, update to the latest version of libplist that addresses the vulnerability.
CVE-2017-5834 is caused by the parse_dict_node function in libplist mishandling crafted files, enabling attackers to exploit it.
CVE-2017-5834 affects libplist within the libimobiledevice suite.
CVE-2017-5834 is associated with denial of service attacks resulting in crashes.