Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-7410

Опубликовано: 23 янв. 2017
Источник: debian
EPSS Низкий

Описание

The _dwarf_read_loc_section function in dwarf_loc.c in libdwarf 20160613 allows attackers to cause a denial of service (buffer over-read) via a crafted file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
dwarfutilsfixed20160923-1package
dwarfutilsnot-affectedjessiepackage
dwarfutilsnot-affectedwheezypackage

Примечания

  • https://www.prevanders.net/dwarfbug.html#DW201609-003

  • http://seclists.org/oss-sec/2016/q3/490

  • Initial addressed upstream in refactoring in:

  • https://sourceforge.net/p/libdwarf/code/ci/e12f6c0b69c20f58dccc4505309cf7f974c34dc2

  • with final fix/follow up: https://sourceforge.net/p/libdwarf/code/ci/3767305debcba8bd7e1c483ae48c509d25399252

  • Introduced by (as confirmed by upstream): https://sourceforge.net/p/libdwarf/code/ci/b446e23dc21704ccd3b76d8945aaf39e4aca8c27

EPSS

Процентиль: 54%
0.00309
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 9 лет назад

The _dwarf_read_loc_section function in dwarf_loc.c in libdwarf 20160613 allows attackers to cause a denial of service (buffer over-read) via a crafted file.

CVSS3: 3.3
redhat
около 9 лет назад

The _dwarf_read_loc_section function in dwarf_loc.c in libdwarf 20160613 allows attackers to cause a denial of service (buffer over-read) via a crafted file.

CVSS3: 5.5
nvd
почти 9 лет назад

The _dwarf_read_loc_section function in dwarf_loc.c in libdwarf 20160613 allows attackers to cause a denial of service (buffer over-read) via a crafted file.

CVSS3: 5.5
github
больше 3 лет назад

The _dwarf_read_loc_section function in dwarf_loc.c in libdwarf 20160613 allows attackers to cause a denial of service (buffer over-read) via a crafted file.

EPSS

Процентиль: 54%
0.00309
Низкий