cbcvebase.
CVE-2016-5029
published 2017-02-17

CVE-2016-5029: The create_fullest_file_path function in libdwarf before 20160923 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted…

medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
The create_fullest_file_path function in libdwarf before 20160923 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted dwarf file.

Affected

4 ranges
VendorProductVersion rangeFixed in
debiandwarfutils< dwarfutils 20160507+git20160523.9086738-1 (bookworm)dwarfutils 20160507+git20160523.9086738-1 (bookworm)
libdwarf_projectlibdwarf>= 1999-12-14 < 2016-09-232016-09-23
xmlsoftlibxslt>= 0 < 1.1.28-2ubuntu0.11.1.28-2ubuntu0.1
xmlsoftlibxslt>= 0 < 1.1.28-2.1ubuntu0.11.1.28-2.1ubuntu0.1

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv6.5MEDIUM