oss-sec mailing list archives

Re: CVE request: multiples vulnerabilities in libplist


From: <cve-assign () mitre org>
Date: Thu, 2 Feb 2017 00:52:34 -0500

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

[] heap-buffer-overflow in parse_dict_node
https://github.com/libimobiledevice/libplist/issues/89

Use CVE-2017-5834.


[] memory allocation error
https://github.com/libimobiledevice/libplist/issues/88

Use CVE-2017-5835.


[] issue in plist_free_data plist.c:185
https://github.com/libimobiledevice/libplist/issues/86

Use CVE-2017-5836.


- -- 
CVE Assignment Team
M/S M300, 202 Burlington Road, Bedford, MA 01730 USA
[ A PGP key is available for encrypted communications at
  http://cve.mitre.org/cve/request_id.html ]
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBCAAGBQJYksbsAAoJEHb/MwWLVhi2rGUQAKodAn16yldAnWkPkpBE5pEr
r1/v83CCzMhnlA4UyBjpPXi4hXuUJzW8epmMCPNpgGyvc/4QV4SYOM9pymd+QoLk
iXnWolB4tKszk3vquL81P871rXzkWHNNIybWpKsPCDRXjoAKJxicma3Rmk8otBWd
fzH8gBUQtShmMojeewPtGZWTubX15sCfXGp7YHczmcSj3k+XdsYf9rfYI5BFaue9
TFypQYqnkCzpkDf/aB7cA3p4kmHieRtkhceY7L2WuP+/kOQ24ABt8y4AJdspA/uH
ufVUgJwWe5/EVJjQDMJCIip5vfJMCTlg1ngz23NcaEhSRQl26zg9nqpDJpLrY+ck
ja22LUfVIbFuZLsj94rl65bMY4sGNXb0VkNSeBIg/HP9ZfiFZPY02uMI0IdIy+6t
T4/HnAUWxdSky9GjlCPl/8kPU5o9O7DRZTiYXbYnYKL/0jKXIHNpJIJVUCq3l8Ty
nH9OwlVBCnq6pcQCIAcwsf5uhgzusjItF2+ufAHL9GeGBN5DtGQP1aAt7b6qEFeC
6ociWZT9megQgGxI/QC+yty75BWszxQw7muqYaEKHUmI3FS/Mu9k53LyM+j+jukd
AIaieeDbNvKzNTM77ECYX5BirD7S8ESb56gyLydt+x2LbtkW9W2Z/6gd8gLbAYEu
ulBMECeaiMBpWZWXOfpp
=Kyb9
-----END PGP SIGNATURE-----


Current thread: