CVE-2016-5038

The dwarf_get_macro_startend_file function in dwarf_macro5.c in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted string offset for .debug_str.
References
Link Resource
http://www.openwall.com/lists/oss-security/2016/05/24/1 Mailing List Patch Third Party Advisory
http://www.openwall.com/lists/oss-security/2016/05/25/1 Exploit Mailing List Third Party Advisory
https://www.prevanders.net/dwarfbug.html Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:libdwarf_project:libdwarf:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2017-02-17 17:59

Updated : 2024-02-28 15:44


NVD link : CVE-2016-5038

Mitre link : CVE-2016-5038

CVE.ORG link : CVE-2016-5038


JSON object : View

Products Affected

libdwarf_project

  • libdwarf
CWE
CWE-125

Out-of-bounds Read