Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-9480

Опубликовано: 29 нояб. 2016
Источник: debian

Описание

libdwarf 2016-10-21 allows context-dependent attackers to obtain sensitive information or cause a denial of service by using the "malformed dwarf file" approach, related to a "Heap Buffer Over-read" issue affecting the dwarf_util.c component, aka DW201611-006.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
dwarfutilsfixed20161124-1package
dwarfutilsno-dsajessiepackage
dwarfutilsno-dsawheezypackage

Примечания

  • https://www.prevanders.net/dwarfbug.html#DW201611-006

  • https://sourceforge.net/p/libdwarf/bugs/5/

  • https://sourceforge.net/p/libdwarf/code/ci/5dd64de047cd5ec479fb11fe7ff2692fd819e5e5/

  • The code has substantially changed in libdwarf/dwarf_util.c from older

  • versions, but there seem to be still back then an unchecked dereference

  • of val_ptr.

Связанные уязвимости

CVSS3: 9.1
ubuntu
больше 8 лет назад

libdwarf 2016-10-21 allows context-dependent attackers to obtain sensitive information or cause a denial of service by using the "malformed dwarf file" approach, related to a "Heap Buffer Over-read" issue affecting the dwarf_util.c component, aka DW201611-006.

CVSS3: 6.5
redhat
почти 9 лет назад

libdwarf 2016-10-21 allows context-dependent attackers to obtain sensitive information or cause a denial of service by using the "malformed dwarf file" approach, related to a "Heap Buffer Over-read" issue affecting the dwarf_util.c component, aka DW201611-006.

CVSS3: 9.1
nvd
больше 8 лет назад

libdwarf 2016-10-21 allows context-dependent attackers to obtain sensitive information or cause a denial of service by using the "malformed dwarf file" approach, related to a "Heap Buffer Over-read" issue affecting the dwarf_util.c component, aka DW201611-006.

CVSS3: 9.1
github
больше 3 лет назад

libdwarf 2016-10-21 allows context-dependent attackers to obtain sensitive information or cause a denial of service by using the "malformed dwarf file" approach, related to a "Heap Buffer Over-read" issue affecting the dwarf_util.c component, aka DW201611-006.