Vulnerabilities > CVE-2016-9275 - Out-of-bounds Write vulnerability in Libdwarf Project Libdwarf

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
network
low complexity
libdwarf-project
CWE-787
nessus

Summary

Heap-based buffer overflow in the _dwarf_skim_forms function in libdwarf/dwarf_macro5.c in Libdwarf before 20161124 allows remote attackers to cause a denial of service (out-of-bounds read).

Vulnerable Configurations

Part Description Count
Application
Libdwarf_Project
170

Common Weakness Enumeration (CWE)

Nessus

  • NASL familyFreeBSD Local Security Checks
    NASL idFREEBSD_PKG_83041CA7D69011E6917114DAE9D210B8.NASL
    descriptionChristian Rebischke reports : libdwarf is vulnerable to multiple issues including arbitrary code execution, information disclosure and denial of service.
    last seen2020-06-01
    modified2020-06-02
    plugin id96368
    published2017-01-10
    reporterThis script is Copyright (C) 2017-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/96368
    titleFreeBSD : libdwarf -- multiple vulnerabilities (83041ca7-d690-11e6-9171-14dae9d210b8)
  • NASL familyFedora Local Security Checks
    NASL idFEDORA_2017-961CD53028.NASL
    descriptionUpdate to libdward 20170416 Note that Tenable Network Security has extracted the preceding description block directly from the Fedora update system website. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-06-05
    modified2017-07-17
    plugin id101685
    published2017-07-17
    reporterThis script is Copyright (C) 2017-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/101685
    titleFedora 26 : libdwarf (2017-961cd53028)
  • NASL familyFedora Local Security Checks
    NASL idFEDORA_2017-15E7445D67.NASL
    descriptionUpdate to libdward 20170416 Note that Tenable Network Security has extracted the preceding description block directly from the Fedora update system website. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.
    last seen2020-06-05
    modified2017-04-26
    plugin id99676
    published2017-04-26
    reporterThis script is Copyright (C) 2017-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/99676
    titleFedora 25 : libdwarf (2017-15e7445d67)