PatchSiren

PatchSiren cyber security CVE debrief

CVE-2017-5835 Libimobiledevice CVE debrief

CVE-2017-5835 is a denial-of-service issue in libplist that can cause large memory allocation and a crash when handling vectors involving an offset size of zero. NVD assigns the issue a CVSS 3.0 score of 7.5 (HIGH) and maps it to CWE-770, indicating uncontrolled resource consumption. The available references include upstream mailing list threads and a GitHub issue tied to the libplist project, which supports the characterization as a resource-exhaustion problem.

Vendor
Libimobiledevice
Product
Libplist
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2017-03-03
Original CVE updated
2026-05-13
Advisory published
2017-03-03
Advisory updated
2026-05-13

Who should care

Organizations that ship, embed, or depend on libplist through libimobiledevice should care, especially if their systems process untrusted or attacker-controlled plist content. Security and operations teams should also review any downstream products that bundle the affected library.

Technical summary

NVD describes the flaw as attacker-triggerable denial of service through large memory allocation and crash behavior related to an offset size of zero. The vulnerability is recorded against cpe:2.3:a:libimobiledevice:libplist:*:*:*:*:*:*:*:* and classified as CWE-770. The CVSS vector (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) indicates remote, low-complexity, no-authentication conditions with high availability impact.

Defensive priority

High for environments that accept untrusted input into libplist, because the issue can be triggered remotely without privileges or user interaction and can consume resources until the service crashes.

Recommended defensive actions

  • Inventory systems and applications that include or depend on libplist.
  • Check whether your deployed libplist package or embedded copy includes a fix for CVE-2017-5835.
  • Prioritize patching or upgrading affected packages in internet-facing or parser-heavy services.
  • Monitor for abnormal memory growth, crashes, or repeated restarts in processes that parse plist data.
  • If immediate patching is not possible, reduce exposure by limiting untrusted plist input paths and isolating the affected component.

Evidence notes

The description, CVSS vector, and CWE mapping come from the NVD record for CVE-2017-5835. The upstream references in the corpus point to libplist-related mailing list discussion and a GitHub issue, which support the resource-exhaustion and crash characterization. The vendor/product mapping in the source corpus uses the libimobiledevice/libplist CPE entry with medium confidence.

Sources and references

Verified primary and authoritative sources

  • CVE-2017-5835 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2017-5835

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2017-5835 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2017-5835

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.