CVE-2015-8750NULL Pointer Dereference in Project Libdwarf

Severity
6.5MEDIUMNVD
EPSS
0.6%
top 30.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 13
Latest updateMay 13

Description

libdwarf 20151114 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a debug_abbrev section marked NOBITS in an ELF file.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages1 packages

NVDlibdwarf_project/libdwarf1999-12-142015-11-14

Patches

🔴Vulnerability Details

3
GHSA
GHSA-q9p8-c796-r5q2: libdwarf 20151114 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a debug_abbrev section mar2022-05-13
OSV
CVE-2015-8750: libdwarf 20151114 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a debug_abbrev section mar2017-02-13
CVEList
CVE-2015-8750: libdwarf 20151114 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a debug_abbrev section mar2017-02-13

📋Vendor Advisories

2
Red Hat
libdwarf: NULL pointer dereference in dwarf_utils.c2015-12-25
Debian
CVE-2015-8750: dwarfutils - libdwarf 20151114 and earlier allows remote attackers to cause a denial of servi...2015

💬Community

2
Bugzilla
CVE-2015-8750 libdwarf: NULL pointer dereference in dwarf_utils.c2016-01-08
Bugzilla
CVE-2015-8750 libdwarf: NULL pointer dereference in dwarf_utils.c [epel-6]2016-01-08
CVE-2015-8750 — NULL Pointer Dereference | cvebase