VDB
GCVE-110-MAGEIA-2018-25
GCVE-110-MAGEIA-2018-25
Advisory Published
The base64decode function in libplist allowed attackers to obtain
sensitive information from process memory or cause a denial of
service (buffer over-read) via split encoded Apple Property List data
(CVE-2017-5209).
The main function in plistutil.c in libimobiledevice libplist allowed
attackers to obtain sensitive information from process memory or cause a
denial of service (buffer over-read) via Apple Property List data that is
too short (CVE-2017-5545).
A heap-buffer overflow in parse_dict_node could cause a segmentation fault
(CVE-2017-5834).
Malicious crafted file could cause libplist to allocate large amounts of
memory and consume lots of CPU because of a memory allocation error
(CVE-2017-5835).
A type inconsistency in bplist.c could cause the application to crash
(CVE-2017-5836).
Crafted plist file could lead to Heap-buffer overflow (CVE-2017-6435).
Integer overflow in parse_string_node (CVE-2017-6436).
The base64encode function in base64.c allows local users to cause denial
of service (out-of-bounds read) via a crafted plist file (CVE-2017-6437).
Heap-based buffer overflow in the parse_unicode_node function
(CVE-2017-6438).
Heap-based buffer overflow in the parse_string_node function
(CVE-2017-6439).
Ensure that sanity checks work on 32-bit platforms (CVE-2017-6440).
Add some safety checks, backported from upstream (CVE-2017-7982).
The gvfs, ifuse, kodi, libgpod, libimobiledevice, upower, and usbmuxd
packages have been rebuilt for the updated libplist.
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | usbmuxd | 0 (affected), 1.0.9-6.2.mga5 (unaffected), 1.0.9-6.2.mga5 (unaffected), 0 (affected) | — |
| Mageia | libplist | 0 (affected), 1.12-1.mga5 (unaffected), 0 (affected), 1.12-1.mga5 (unaffected) | — |
| Mageia | gdk-pixbuf2.0 | 0 (affected), 2.32.3-1.3.mga5 (unaffected) | — |
| Mageia | libimobiledevice | 0 (affected), 1.1.6-4.2.mga5 (unaffected), 0 (affected), 1.1.6-4.2.mga5 (unaffected) | — |
| Mageia | ifuse | 0 (affected), 1.1.3-4.1.mga5 (unaffected), 1.1.3-4.1.mga5 (unaffected), 0 (affected) | — |
| Mageia | kodi | 0 (affected), 14.0-2.3.mga5 (unaffected), 0 (affected), 14.0-2.3.mga5 (unaffected) | — |
| Mageia | libgpod | 0 (affected), 0.8.3-8.2.mga5 (unaffected), 0 (affected), 0.8.3-8.2.mga5 (unaffected) | — |
| Mageia | upower | 0 (affected), 0.99.2-1.2.mga5 (unaffected), 0.99.2-1.2.mga5 (unaffected), 0 (affected) | — |
| Mageia | gvfs | 0 (affected), 1.22.3-2.2.mga5 (unaffected), 1.22.3-2.2.mga5 (unaffected), 0 (affected) | — |
References
Browse GCVE Records
74,198 records in the GCVE database · Updated July 21, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.