CVE-2017-6435

Source
https://nvd.nist.gov/vuln/detail/CVE-2017-6435
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-6435.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2017-6435
Downstream
Related
Published
2017-03-15T14:59:00Z
Modified
2025-10-15T09:03:13.326537Z
Severity
  • 5.0 (Medium) CVSS_V3 - CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

The parsestringnode function in bplist.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (memory corruption) via a crafted plist file.

References

Affected packages

Git / github.com/libimobiledevice/libplist

Affected ranges

Type
GIT
Repo
https://github.com/libimobiledevice/libplist
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

1.*

1.10
1.11
1.12
1.4
1.5
1.6
1.7
1.8
1.9

Other

libplist_rc1
libplist_rc2

v0.*

v0.10
v0.11
v0.12
v0.13
v0.14
v0.15
v0.16
v0.8
v0.9

v1.*

v1.0
v1.1
v1.2
v1.3

Database specific

vanir_signatures

[
    {
        "signature_version": "v1",
        "id": "CVE-2017-6435-15f9e459",
        "source": "https://github.com/libimobiledevice/libplist/commit/fbd8494d5e4e46bf2e90cb6116903e404374fb56",
        "digest": {
            "line_hashes": [
                "166617824543065401546292462610535510105",
                "151939609487479776985276108744903120935",
                "24133642741013801621014912325641290436",
                "37113499254304029301144506171486364652"
            ],
            "threshold": 0.9
        },
        "deprecated": false,
        "target": {
            "file": "src/bplist.c"
        },
        "signature_type": "Line"
    },
    {
        "signature_version": "v1",
        "id": "CVE-2017-6435-c2e66383",
        "source": "https://github.com/libimobiledevice/libplist/commit/fbd8494d5e4e46bf2e90cb6116903e404374fb56",
        "digest": {
            "length": 355.0,
            "function_hash": "131114131073426878372943962157941285538"
        },
        "deprecated": false,
        "target": {
            "function": "parse_string_node",
            "file": "src/bplist.c"
        },
        "signature_type": "Function"
    }
]