Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-34299

Опубликовано: 23 июн. 2022
Источник: redhat
CVSS3: 7.1
EPSS Низкий

Описание

There is a heap-based buffer over-read in libdwarf 0.4.0. This issue is related to dwarf_global_formref_b.

A buffer-overflow vulnerability was found in libdwarf's dwarf_global_formref_b() function in dwarf_form.c. A carefully crafted .debug_info causes libdwarf to read outside a buffer containing a Dwarf_Sig8 symbolic reference. This issue can cause a segmentation violation or other major error, terminating the calling application and resulting in a denial of service.

Отчет

The bug has been present since DWARF4 when DW_FORM_ref_sig8 was added to libdwarf. But, in our code-base, we cannot handle this functionality yet. There is no presence of vulnerable code in our code-base. Hence, versions of libdwarf shipped with Red Hat Enterprise Linux 7 & 8 are not affected by this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7libdwarfNot affected
Red Hat Enterprise Linux 8libdwarfNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-126
https://bugzilla.redhat.com/show_bug.cgi?id=2102019libdwarf: heap buffer over-read in dwarf_global_formref_b() in dwarf_form.c

EPSS

Процентиль: 45%
0.00227
Низкий

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
больше 3 лет назад

There is a heap-based buffer over-read in libdwarf 0.4.0. This issue is related to dwarf_global_formref_b.

CVSS3: 8.1
nvd
больше 3 лет назад

There is a heap-based buffer over-read in libdwarf 0.4.0. This issue is related to dwarf_global_formref_b.

CVSS3: 8.1
debian
больше 3 лет назад

There is a heap-based buffer over-read in libdwarf 0.4.0. This issue i ...

CVSS3: 8.1
github
больше 3 лет назад

There is a heap-based buffer over-read in libdwarf 0.4.0. This issue is related to dwarf_global_formref_b.

EPSS

Процентиль: 45%
0.00227
Низкий

7.1 High

CVSS3