Bug 1470186 (CVE-2017-9998) - CVE-2017-9998 libdwarf: Segmentation fault in the _dwarf_decode_s_leb128_chk function
Summary: CVE-2017-9998 libdwarf: Segmentation fault in the _dwarf_decode_s_leb128_chk ...
Keywords:
Status: CLOSED WONTFIX
Alias: CVE-2017-9998
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1470187 1470188
Blocks:
TreeView+ depends on / blocked
 
Reported: 2017-07-12 13:47 UTC by Andrej Nemec
Modified: 2021-02-17 01:56 UTC (History)
2 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2017-07-12 13:48:44 UTC


Attachments (Terms of Use)

Description Andrej Nemec 2017-07-12 13:47:33 UTC
The _dwarf_decode_s_leb128_chk function in dwarf_leb.c in libdwarf through 2017-06-28 allows attackers to cause a denial of service (Segmentation fault) via a crafted file.

Product bug:

https://bugzilla.redhat.com/show_bug.cgi?id=1465756

Comment 1 Andrej Nemec 2017-07-12 13:47:52 UTC
Created libdwarf tracking bugs for this issue:

Affects: epel-6 [bug 1470187]
Affects: fedora-all [bug 1470188]

Comment 2 Andrej Nemec 2017-07-12 13:48:51 UTC
Acknowledgments:

Name: OWL337 Team


Note You need to log in before you can comment on or make changes to this bug.