PT-2022-24357 · Lief · Lief

Ccwang19

·

Published

2022-09-13

·

Updated

2023-08-08

·

CVE-2022-38307

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions LIEF version 5d1d643
Description A segmentation violation was discovered in LIEF via the function LIEF::MachO::SegmentCommand::file offset() at /MachO/SegmentCommand.cpp.
Recommendations For LIEF version 5d1d643, update to a version that includes the patch from commit 7acf0bc4224081d4f425fcc8b2e361b95291d878 to resolve the issue.

Exploit

Fix

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

CVE-2022-38307
GHSA-X2XX-JW5M-5J86
PYSEC-2022-275

Affected Products

Lief