The main function in plistutil.c in libimobiledevice libplist allows attackers to obtain sensitive information from process memory or cause a denial of service (buffer over-read) via Apple Property List data that is too short. Upstream bug: https://github.com/libimobiledevice/libplist/issues/87 Upstream patch: https://github.com/libimobiledevice/libplist/commit/7391a506352c009fe044dead7baad9e22dd279ee
Created libplist tracking bugs for this issue: Affects: fedora-all [bug 1416008]