PT-2017-9184 · Libdwarf · Libdwarf
F4B3Cd
·
Publicado
2017-01-23
·
Atualizado
2022-04-11
·
CVE-2016-7410
CVSS v3.1
5.5
Média
| Vetor | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
libdwarf version 20160613
Description
The issue allows attackers to cause a denial of service, specifically a buffer over-read, by using a crafted file. This is related to the
dwarf read loc section function in dwarf loc.c.Recommendations
For libdwarf version 20160613, consider avoiding the use of crafted files that may trigger the buffer over-read issue until a patch is available. As a temporary workaround, restrict access to potentially malicious files to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.
Exploit
Correção
Out of bounds Read
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Libdwarf