A null pointer dereference vulnerability was found in libdwarf in create_fullest_file_path() function. This is due to corrupted dwarf and the fix detects this corruption and if that null string pointer happens undetected a static string is substituted so readers can notice the situation. References (with a link to PoC): http://seclists.org/oss-sec/2016/q2/393 External references: https://www.prevanders.net/dwarfbug.html Upstream fix: https://sourceforge.net/p/libdwarf/code/ci/acae971371daa23a19358bc62204007d258fbc5e
If you want to report an issue with the Fedora package then please do so against the proper component. In the meantime please stop adding me to your RedHat internal security bugs.
Created libdwarf tracking bugs for this issue: Affects: fedora-all [bug 1340128] Affects: epel-6 [bug 1340129]