PatchSiren cyber security CVE debrief
CVE-2017-5835 Libimobiledevice CVE debrief
CVE-2017-5835 is a denial-of-service issue in libplist that can cause large memory allocation and a crash when handling vectors involving an offset size of zero. NVD assigns the issue a CVSS 3.0 score of 7.5 (HIGH) and maps it to CWE-770, indicating uncontrolled resource consumption. The available references include upstream mailing list threads and a GitHub issue tied to the libplist project, which supports the characterization as a resource-exhaustion problem.
- Vendor
- Libimobiledevice
- Product
- Libplist
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-03-03
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-03-03
- Advisory updated
- 2026-05-13
Who should care
Organizations that ship, embed, or depend on libplist through libimobiledevice should care, especially if their systems process untrusted or attacker-controlled plist content. Security and operations teams should also review any downstream products that bundle the affected library.
Technical summary
NVD describes the flaw as attacker-triggerable denial of service through large memory allocation and crash behavior related to an offset size of zero. The vulnerability is recorded against cpe:2.3:a:libimobiledevice:libplist:*:*:*:*:*:*:*:* and classified as CWE-770. The CVSS vector (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) indicates remote, low-complexity, no-authentication conditions with high availability impact.
Defensive priority
High for environments that accept untrusted input into libplist, because the issue can be triggered remotely without privileges or user interaction and can consume resources until the service crashes.
Recommended defensive actions
- Inventory systems and applications that include or depend on libplist.
- Check whether your deployed libplist package or embedded copy includes a fix for CVE-2017-5835.
- Prioritize patching or upgrading affected packages in internet-facing or parser-heavy services.
- Monitor for abnormal memory growth, crashes, or repeated restarts in processes that parse plist data.
- If immediate patching is not possible, reduce exposure by limiting untrusted plist input paths and isolating the affected component.
Evidence notes
The description, CVSS vector, and CWE mapping come from the NVD record for CVE-2017-5835. The upstream references in the corpus point to libplist-related mailing list discussion and a GitHub issue, which support the resource-exhaustion and crash characterization. The vendor/product mapping in the source corpus uses the libimobiledevice/libplist CPE entry with medium confidence.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-5835 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-5835
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-5835 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-5835
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/libimobiledevice/libplist/issues/88
[email protected] - Issue Tracking, Patch, Third Party Advisory
-
Source reference
Unverified legacy reference
URL: https://lists.debian.org/debian-lts-announce/2020/04/msg00002.html
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.