PT-2022-25620 · Lief · Lief
Bladchan
·
Published
2022-10-03
·
Updated
2022-10-05
·
CVE-2022-40922
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
LIEF version 0.12.1
Description
A vulnerability in the LIEF::MachO::BinaryParser::init and parse function allows attackers to cause a denial of service (DOS) through a segmentation fault via a crafted MachO file.
Recommendations
For LIEF version 0.12.1, update to a version that includes the fix committed at fde2c48986739fabd2cf9b40b9af149a89c57850 to resolve the issue. As a temporary workaround, consider avoiding the use of the
init and parse function in the LIEF::MachO::BinaryParser until a patch is applied.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Lief