Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-3239

Опубликовано: 20 июн. 2015
Источник: redhat
CVSS2: 3.3

Описание

Off-by-one error in the dwarf_to_unw_regnum function in include/dwarf_i.h in libunwind 1.1 allows local users to have unspecified impact via invalid dwarf opcodes.

An off-by-one array indexing error was found in the libunwind API, which could cause an error when reading untrusted binaries or dwarf debug info data. Red Hat products do not call the API in this way; and it is unlikely that any exploitable attack vector exists in current builds or supported usage.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ceph Storage 1.1libunwindWill not fix
Red Hat Ceph Storage 1.2libunwindWill not fix
Red Hat Enterprise Linux 5libunwindNot affected
Red Hat Enterprise Linux 7libunwindNot affected
Red Hat Enterprise Linux OpenStack Platform 6 (Juno) InstallerlibunwindWill not fix
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)libunwindNot affected
Red Hat Software Collectionsmongodb24-libunwindWill not fix
Red Hat Software Collectionsrh-mongodb26-libunwindWill not fix
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6libunwindFixedRHSA-2015:176810.09.2015
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7libunwindFixedRHSA-2015:176910.09.2015

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-193
https://bugzilla.redhat.com/show_bug.cgi?id=1232265libunwind: off-by-one in dwarf_to_unw_regnum()

3.3 Low

CVSS2

Связанные уязвимости

ubuntu
больше 10 лет назад

Off-by-one error in the dwarf_to_unw_regnum function in include/dwarf_i.h in libunwind 1.1 allows local users to have unspecified impact via invalid dwarf opcodes.

nvd
больше 10 лет назад

Off-by-one error in the dwarf_to_unw_regnum function in include/dwarf_i.h in libunwind 1.1 allows local users to have unspecified impact via invalid dwarf opcodes.

debian
больше 10 лет назад

Off-by-one error in the dwarf_to_unw_regnum function in include/dwarf_ ...

suse-cvrf
около 7 лет назад

Security update for libunwind

suse-cvrf
почти 7 лет назад

Security update for libunwind

3.3 Low

CVSS2