Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-2002

Опубликовано: 17 фев. 2024
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A double-free vulnerability was found in libdwarf. In a multiply-corrupted DWARF object, libdwarf may try to dealloc(free) an allocation twice, potentially causing unpredictable and various results.

Отчет

The double deallocation issue in libdwarf represents a moderate severity concern due to its potential to cause memory corruption and undefined behavior within the application. When memory is deallocated twice, it can lead to a range of unpredictable outcomes, including crashes, data corruption, and vulnerabilities that could be exploited maliciously. In a multi-threaded environment or in complex applications relying on libdwarf, such issues can be particularly challenging to diagnose and rectify. Additionally, the inconsistency in memory management can propagate errors across different parts of the software, complicating debugging efforts and potentially compromising the stability and security of the system..

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7libdwarfOut of support scope
Red Hat Enterprise Linux 8libdwarfNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-415
https://bugzilla.redhat.com/show_bug.cgi?id=2267700libdwarf: crashes randomly on fuzzed object

EPSS

Процентиль: 30%
0.00106
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 1 года назад

A double-free vulnerability was found in libdwarf. In a multiply-corrupted DWARF object, libdwarf may try to dealloc(free) an allocation twice, potentially causing unpredictable and various results.

CVSS3: 7.5
nvd
больше 1 года назад

A double-free vulnerability was found in libdwarf. In a multiply-corrupted DWARF object, libdwarf may try to dealloc(free) an allocation twice, potentially causing unpredictable and various results.

CVSS3: 7.5
msrc
больше 1 года назад

Описание отсутствует

CVSS3: 7.5
debian
больше 1 года назад

A double-free vulnerability was found in libdwarf. In a multiply-corru ...

CVSS3: 7.5
redos
9 месяцев назад

Уязвимость libdwarf

EPSS

Процентиль: 30%
0.00106
Низкий

7.5 High

CVSS3