Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-39170

Опубликовано: 02 сент. 2022
Источник: redhat
CVSS3: 6.5

Описание

libdwarf 0.4.1 has a double free in _dwarf_exec_frame_instr in dwarf_frame.c.

A double-free vulnerability was found in libdwarf's dwarf_expand_frame_instructions() function of the dwarf_frame.c file. A carefully crafted object file could cause the ‘dwarfdump' utility to do a double free in handling an error condition. This issue could cause a segmentation violation or other major error, terminating the calling application and resulting in a denial of service.

Отчет

The vulnerable code was introduced upstream in libdwarf-0.3.0, and later, Red Hat ships lower versions of libdwarf, which do not contain the vulnerable code. Hence, versions of libdwarf shipped with Red Hat Enterprise Linux 7 & 8 are not affected by this CVE.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7libdwarfNot affected
Red Hat Enterprise Linux 8libdwarfNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-415
https://bugzilla.redhat.com/show_bug.cgi?id=2126424libdwarf: double free in _dwarf_exec_frame_instr() in dwarf_frame.c

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 3 лет назад

libdwarf 0.4.1 has a double free in _dwarf_exec_frame_instr in dwarf_frame.c.

CVSS3: 8.8
nvd
больше 3 лет назад

libdwarf 0.4.1 has a double free in _dwarf_exec_frame_instr in dwarf_frame.c.

CVSS3: 8.8
debian
больше 3 лет назад

libdwarf 0.4.1 has a double free in _dwarf_exec_frame_instr in dwarf_f ...

CVSS3: 8.8
github
больше 3 лет назад

libdwarf 0.4.1 has a double free in _dwarf_exec_frame_instr in dwarf_frame.c.

6.5 Medium

CVSS3