A null pointer dereference vulnerability was found in libdwarf. It exists due to a corrupted object file. Libdwarf was not dealing with empty (bss-like) sections since it really did not expect to see such in sections it reads. Now libdwarf catches the object error so dwarfdump sees the section as empty. References (with a link to PoC): http://seclists.org/oss-sec/2016/q2/393 External references: https://www.prevanders.net/dwarfbug.html Upstream fix: https://sourceforge.net/p/libdwarf/code/ci/a55b958926cc67f89a512ed30bb5a22b0adb10f4
If you want to report an issue with the Fedora package then please do so against the proper component. In the meantime please stop adding me to your RedHat internal security bugs.
Created libdwarf tracking bugs for this issue: Affects: fedora-all [bug 1340128] Affects: epel-6 [bug 1340129]