Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-2050

Опубликовано: 31 янв. 2017
Источник: debian

Описание

The get_abbrev_array_info function in libdwarf-20151114 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted elf file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
dwarfutilsfixed20160507+git20160523.9086738-1package
dwarfutilsfixed20120410-2+deb8u1jessiepackage

Примечания

  • https://www.openwall.com/lists/oss-security/2016/01/19/9

  • Fixed by http://sourceforge.net/p/libdwarf/code/ci/a05f5e2ae6a5f34daa566975894fc2803d6ec684

  • Reasoning for "unimportant" severity: The affected source code is present

  • in dwarfdump/, but in the binary package is installed dwarfdump2/ .

  • dwarfdump2 (the C++ implentation) has been abandoned again by upstream in

  • fawour of the C version.

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 9 лет назад

The get_abbrev_array_info function in libdwarf-20151114 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted elf file.

redhat
около 10 лет назад

The get_abbrev_array_info function in libdwarf-20151114 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted elf file.

CVSS3: 6.5
nvd
около 9 лет назад

The get_abbrev_array_info function in libdwarf-20151114 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted elf file.

CVSS3: 6.5
github
больше 3 лет назад

The get_abbrev_array_info function in libdwarf-20151114 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted elf file.