CVE-2015-8750
published 2017-02-13CVE-2015-8750: libdwarf 20151114 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a debug_abbrev section marked…
PriorityP425medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
1.90%
77.4th percentile
libdwarf 20151114 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a debug_abbrev section marked NOBITS in an ELF file.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | dwarfutils | < dwarfutils 20160507-1 (bookworm) | dwarfutils 20160507-1 (bookworm) |
| libdwarf_project | libdwarf | 1999-12-14 – 2015-11-14 | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-q9p8-c796-r5q2: libdwarf 20151114 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a debug_abbrev section mar
ghsa_unreviewed·2022-05-13
CVE-2015-8750 [MEDIUM] CWE-476 GHSA-q9p8-c796-r5q2: libdwarf 20151114 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a debug_abbrev section mar
libdwarf 20151114 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a debug_abbrev section marked NOBITS in an ELF file.
OSV
CVE-2015-8750: libdwarf 20151114 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a debug_abbrev section mar
osv·2017-02-13·CVSS 6.5
CVE-2015-8750 [MEDIUM] CVE-2015-8750: libdwarf 20151114 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a debug_abbrev section mar
libdwarf 20151114 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a debug_abbrev section marked NOBITS in an ELF file.
Red Hat
libdwarf: NULL pointer dereference in dwarf_utils.c
vendor_redhat·2015-12-25·CVSS 6.5
CVE-2015-8750 [MEDIUM] CWE-476 libdwarf: NULL pointer dereference in dwarf_utils.c
libdwarf: NULL pointer dereference in dwarf_utils.c
libdwarf 20151114 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a debug_abbrev section marked NOBITS in an ELF file.
Package: libdwarf (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2015-8750: dwarfutils - libdwarf 20151114 and earlier allows remote attackers to cause a denial of servi...
vendor_debian·2015·CVSS 6.5
CVE-2015-8750 [MEDIUM] CVE-2015-8750: dwarfutils - libdwarf 20151114 and earlier allows remote attackers to cause a denial of servi...
libdwarf 20151114 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a debug_abbrev section marked NOBITS in an ELF file.
Scope: local
bookworm: resolved (fixed in 20160507-1)
bullseye: resolved (fixed in 20160507-1)
forky: resolved (fixed in 20160507-1)
sid: resolved (fixed in 20160507-1)
trixie: resolved (fixed in 20160507-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-8750 libdwarf: NULL pointer dereference in dwarf_utils.c
bugzilla·2016-01-08·CVSS 6.5
CVE-2015-8750 [MEDIUM] CVE-2015-8750 libdwarf: NULL pointer dereference in dwarf_utils.c
CVE-2015-8750 libdwarf: NULL pointer dereference in dwarf_utils.c
A null pointer dereference was found in the libdwarf package. This flaw may result in a crash with specially crafted input.
This was originally filed as bug 1294264.
CVE assignment:
http://seclists.org/oss-sec/2016/q1/45
Upstream patch:
11750a2838e52953013e3114ef27b3c7b1780697
in
git://git.code.sf.net/p/libdwarf/code
Also available on GitHub:
https://github.com/tomhughes/libdwarf/commit/11750a2838e52953013e3114ef27b3c7b1780697
Discussion:
Created libdwarf tracking bugs for this issue:
Affects: epel-6 [bug 1296989]
---
BTW my github repo is not the upstream... The upstream is the repo at git://git.code.sf.net/p/libdwarf/code.
---
(In reply to Tom Hughes from comment #2)
> BTW my github repo is not the upstream.
Bugzilla
CVE-2015-8750 libdwarf: NULL pointer dereference in dwarf_utils.c [epel-6]
bugzilla·2016-01-08·CVSS 6.5
CVE-2015-8750 [MEDIUM] CVE-2015-8750 libdwarf: NULL pointer dereference in dwarf_utils.c [epel-6]
CVE-2015-8750 libdwarf: NULL pointer dereference in dwarf_utils.c [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
epel-6 tracking bug for libdwarf: see blocks bug list
http://www.openwall.com/lists/oss-security/2016/01/07/11https://bugzilla.redhat.com/show_bug.cgi?id=1294264https://github.com/tomhughes/libdwarf/commit/11750a2838e52953013e3114ef27b3c7b1780697http://www.openwall.com/lists/oss-security/2016/01/07/11https://bugzilla.redhat.com/show_bug.cgi?id=1294264https://github.com/tomhughes/libdwarf/commit/11750a2838e52953013e3114ef27b3c7b1780697
2017-02-13
Published