CVE-2016-7510
published 2017-02-17CVE-2016-7510: The read_line_table_program function in dwarf_line_table_reader_common.c in libdwarf before 20160923 allows remote attackers to cause a denial of service…
PriorityP426medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
1.62%
73.6th percentile
The read_line_table_program function in dwarf_line_table_reader_common.c in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds read) via crafted input.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | dwarfutils | < dwarfutils 20160923-1 (bookworm) | dwarfutils 20160923-1 (bookworm) |
| libdwarf_project | libdwarf | >= 1999-12-14 < 2016-09-23 | 2016-09-23 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
libdwarf: Out-of-bounds read in read_line_table_program
vendor_redhat·2016-09-17·CVSS 6.5
CVE-2016-7510 [MEDIUM] CWE-125 libdwarf: Out-of-bounds read in read_line_table_program
libdwarf: Out-of-bounds read in read_line_table_program
The read_line_table_program function in dwarf_line_table_reader_common.c in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds read) via crafted input.
Package: libdwarf (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2016-7510: dwarfutils - The read_line_table_program function in dwarf_line_table_reader_common.c in libd...
vendor_debian·2016·CVSS 6.5
CVE-2016-7510 [MEDIUM] CVE-2016-7510: dwarfutils - The read_line_table_program function in dwarf_line_table_reader_common.c in libd...
The read_line_table_program function in dwarf_line_table_reader_common.c in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds read) via crafted input.
Scope: local
bookworm: resolved (fixed in 20160923-1)
bullseye: resolved (fixed in 20160923-1)
forky: resolved (fixed in 20160923-1)
sid: resolved (fixed in 20160923-1)
trixie: resolved (fixed in 20160923-1)
GHSA
GHSA-fqc2-jvfr-67vv: The read_line_table_program function in dwarf_line_table_reader_common
ghsa_unreviewed·2022-05-13
CVE-2016-7510 [MEDIUM] CWE-125 GHSA-fqc2-jvfr-67vv: The read_line_table_program function in dwarf_line_table_reader_common
The read_line_table_program function in dwarf_line_table_reader_common.c in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds read) via crafted input.
OSV
CVE-2016-7510: The read_line_table_program function in dwarf_line_table_reader_common
osv·2017-02-17·CVSS 6.5
CVE-2016-7510 [MEDIUM] CVE-2016-7510: The read_line_table_program function in dwarf_line_table_reader_common
The read_line_table_program function in dwarf_line_table_reader_common.c in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds read) via crafted input.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-7510 libdwarf: Out-of-bounds read in read_line_table_program
bugzilla·2016-09-23·CVSS 6.5
CVE-2016-7510 [MEDIUM] CVE-2016-7510 libdwarf: Out-of-bounds read in read_line_table_program
CVE-2016-7510 libdwarf: Out-of-bounds read in read_line_table_program
An out-of-bounds read vulnerability was found in libdwarf-20160613.
Original bug report (contains reproducer):
https://bugzilla.redhat.com/show_bug.cgi?id=1377015
Discussion:
Created libdwarf tracking bugs for this issue:
Affects: fedora-all [bug 1378719]
Affects: epel-6 [bug 1378720]
---
*** Bug 1377015 has been marked as a duplicate of this bug. ***
---
*** This bug has been marked as a duplicate of bug 1377015 ***
---
(In reply to Tom Hughes from comment #3)
>
> *** This bug has been marked as a duplicate of bug 1377015 ***
Please, don't close and reopen these bugs at your will. Flaw bugs should manipulated only by Product Security members.
Bugzilla
CVE-2016-7510 libdwarf: Out-of-bounds read in read_line_table_program [epel-6]
bugzilla·2016-09-23·CVSS 6.5
CVE-2016-7510 [MEDIUM] CVE-2016-7510 libdwarf: Out-of-bounds read in read_line_table_program [epel-6]
CVE-2016-7510 libdwarf: Out-of-bounds read in read_line_table_program [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
[bug automatically created by: add-tracking-bugs]
Bugzilla
CVE-2016-7510 libdwarf: Out-of-bounds read in read_line_table_program [fedora-all]
bugzilla·2016-09-23·CVSS 6.5
CVE-2016-7510 [MEDIUM] CVE-2016-7510 libdwarf: Out-of-bounds read in read_line_table_program [fedora-all]
CVE-2016-7510 libdwarf: Out-of-bounds read in read_line_table_program [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported version
2017-02-17
Published