The parse_dict_node function in bplist.c in libplist allows attackers to cause a denial of service (out-of-bounds heap read and crash) via a crafted file.
https://lists.debian.org/debian-lts-announce/2020/04/msg00002.html
https://github.com/libimobiledevice/libplist/issues/89
http://www.securityfocus.com/bid/96022