PT-2017-9184 · Libdwarf · Libdwarf
F4B3Cd
·
Published
2017-01-23
·
Updated
2022-04-11
·
CVE-2016-7410
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
libdwarf version 20160613
Description
The issue allows attackers to cause a denial of service, specifically a buffer over-read, by using a crafted file. This is related to the
dwarf read loc section function in dwarf loc.c.Recommendations
For libdwarf version 20160613, consider avoiding the use of crafted files that may trigger the buffer over-read issue until a patch is available. As a temporary workaround, restrict access to potentially malicious files to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.
Exploit
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Libdwarf