cbcvebase.

Debian Dwarfutils vulnerabilities

42 known vulnerabilities affecting debian/dwarfutils.

Total CVEs
42
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH13MEDIUM21LOW2

Vulnerabilities

Page 1 of 3
CVE-2016-9558P3CRITICALCVSS 9.8fixed in dwarfutils 20161124-1 (bookworm)2016
CVE-2016-9558 [CRITICAL] CVE-2016-9558: dwarfutils - (1) libdwarf/dwarf_leb.c and (2) dwarfdump/print_frames.c in libdwarf before 201... (1) libdwarf/dwarf_leb.c and (2) dwarfdump/print_frames.c in libdwarf before 20161124 allow remote attackers to have unspecified impact via a crafted bit pattern in a signed leb number, aka a "negation overflow." Scope: local bookworm: resolved (fixed in 20161124-1) bullseye: resolved (fixed in 20161124-1) forky: resolved (fixed in 20161124-1) sid: resolved (fi
debian
CVE-2016-9480P3CRITICALCVSS 9.1fixed in dwarfutils 20161124-1 (bookworm)2016
CVE-2016-9480 [CRITICAL] CVE-2016-9480: dwarfutils - libdwarf 2016-10-21 allows context-dependent attackers to obtain sensitive infor... libdwarf 2016-10-21 allows context-dependent attackers to obtain sensitive information or cause a denial of service by using the "malformed dwarf file" approach, related to a "Heap Buffer Over-read" issue affecting the dwarf_util.c component, aka DW201611-006. Scope: local bookworm: resolved (fixed in 20161124-1) bullseye: resolved (fixed in 20161124-1) forky:
debian
CVE-2017-9052P3CRITICALCVSS 9.8fixed in dwarfutils 20170416-2 (bookworm)2017
CVE-2017-9052 [CRITICAL] CVE-2017-9052: dwarfutils - An issue, also known as DW201703-006, was discovered in libdwarf 2017-03-21. A h... An issue, also known as DW201703-006, was discovered in libdwarf 2017-03-21. A heap-based buffer over-read in dwarf_formsdata() is due to a failure to check a pointer for being in bounds (in a few places in this function) and a failure in a check in dwarf_attr_list(). Scope: local bookworm: resolved (fixed in 20170416-2) bullseye: resolved (fixed in 20170416-2)
debian
CVE-2017-9055P3CRITICALCVSS 9.8fixed in dwarfutils 20170416-2 (bookworm)2017
CVE-2017-9055 [CRITICAL] CVE-2017-9055: dwarfutils - An issue, also known as DW201703-001, was discovered in libdwarf 2017-03-21. In ... An issue, also known as DW201703-001, was discovered in libdwarf 2017-03-21. In dwarf_formsdata() a few data types were not checked for being in bounds, leading to a heap-based buffer over-read. Scope: local bookworm: resolved (fixed in 20170416-2) bullseye: resolved (fixed in 20170416-2) forky: resolved (fixed in 20170416-2) sid: resolved (fixed in 20170416-2)
debian
CVE-2017-9054P3CRITICALCVSS 9.8fixed in dwarfutils 20170416-2 (bookworm)2017
CVE-2017-9054 [CRITICAL] CVE-2017-9054: dwarfutils - An issue, also known as DW201703-002, was discovered in libdwarf 2017-03-21. In ... An issue, also known as DW201703-002, was discovered in libdwarf 2017-03-21. In _dwarf_decode_s_leb128_chk() a byte pointer was dereferenced just before it was checked for being in bounds, leading to a heap-based buffer over-read. Scope: local bookworm: resolved (fixed in 20170416-2) bullseye: resolved (fixed in 20170416-2) forky: resolved (fixed in 20170416-2)
debian
CVE-2017-9053P3CRITICALCVSS 9.1fixed in dwarfutils 20170416-2 (bookworm)2017
CVE-2017-9053 [CRITICAL] CVE-2017-9053: dwarfutils - An issue, also known as DW201703-005, was discovered in libdwarf 2017-03-21. A h... An issue, also known as DW201703-005, was discovered in libdwarf 2017-03-21. A heap-based buffer over-read in _dwarf_read_loc_expr_op() is due to a failure to check a pointer for being in bounds (in a few places in this function). Scope: local bookworm: resolved (fixed in 20170416-2) bullseye: resolved (fixed in 20170416-2) forky: resolved (fixed in 20170416-2)
debian
CVE-2016-5044P3HIGHCVSS 7.5fixed in dwarfutils 20160507-1 (bookworm)2016
CVE-2016-5044 [HIGH] CVE-2016-5044: dwarfutils - The WRITE_UNALIGNED function in dwarf_elf_access.c in libdwarf before 20160923 a... The WRITE_UNALIGNED function in dwarf_elf_access.c in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds write and crash) via a crafted DWARF section. Scope: local bookworm: resolved (fixed in 20160507-1) bullseye: resolved (fixed in 20160507-1) forky: resolved (fixed in 20160507-1) sid: resolved (fixed in 20160507-1) trixi
debian
CVE-2016-9275P3HIGHCVSS 7.5fixed in dwarfutils 20161124-1 (bookworm)2016
CVE-2016-9275 [HIGH] CVE-2016-9275: dwarfutils - Heap-based buffer overflow in the _dwarf_skim_forms function in libdwarf/dwarf_m... Heap-based buffer overflow in the _dwarf_skim_forms function in libdwarf/dwarf_macro5.c in Libdwarf before 20161124 allows remote attackers to cause a denial of service (out-of-bounds read). Scope: local bookworm: resolved (fixed in 20161124-1) bullseye: resolved (fixed in 20161124-1) forky: resolved (fixed in 20161124-1) sid: resolved (fixed in 20161124-1) trixie:
debian
CVE-2016-5036P3HIGHCVSS 7.5fixed in dwarfutils 20160507+git20160523.9086738-1 (bookworm)2016
CVE-2016-5036 [HIGH] CVE-2016-5036: dwarfutils - The dump_block function in print_sections.c in libdwarf before 20160923 allows r... The dump_block function in print_sections.c in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds read) via crafted frame data. Scope: local bookworm: resolved (fixed in 20160507+git20160523.9086738-1) bullseye: resolved (fixed in 20160507+git20160523.9086738-1) forky: resolved (fixed in 20160507+git20160523.9086738-1) sid:
debian
CVE-2016-5042P3HIGHCVSS 7.5fixed in dwarfutils 20160507-1 (bookworm)2016
CVE-2016-5042 [HIGH] CVE-2016-5042: dwarfutils - The dwarf_get_aranges_list function in libdwarf before 20160923 allows remote at... The dwarf_get_aranges_list function in libdwarf before 20160923 allows remote attackers to cause a denial of service (infinite loop and crash) via a crafted DWARF section. Scope: local bookworm: resolved (fixed in 20160507-1) bullseye: resolved (fixed in 20160507-1) forky: resolved (fixed in 20160507-1) sid: resolved (fixed in 20160507-1) trixie: resolved (fixed in
debian
CVE-2016-5043P3HIGHCVSS 7.5fixed in dwarfutils 20160507-1 (bookworm)2016
CVE-2016-5043 [HIGH] CVE-2016-5043: dwarfutils - The dwarf_dealloc function in libdwarf before 20160923 allows remote attackers t... The dwarf_dealloc function in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted DWARF section. Scope: local bookworm: resolved (fixed in 20160507-1) bullseye: resolved (fixed in 20160507-1) forky: resolved (fixed in 20160507-1) sid: resolved (fixed in 20160507-1) trixie: resolved (fixed in 201
debian
CVE-2016-5038P3HIGHCVSS 7.5fixed in dwarfutils 20160507+git20160523.9086738-1 (bookworm)2016
CVE-2016-5038 [HIGH] CVE-2016-5038: dwarfutils - The dwarf_get_macro_startend_file function in dwarf_macro5.c in libdwarf before ... The dwarf_get_macro_startend_file function in dwarf_macro5.c in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted string offset for .debug_str. Scope: local bookworm: resolved (fixed in 20160507+git20160523.9086738-1) bullseye: resolved (fixed in 20160507+git20160523.9086738-1) forky: resolved (fixed in
debian
CVE-2016-5039P3HIGHCVSS 7.5fixed in dwarfutils 20160507-1 (bookworm)2016
CVE-2016-5039 [HIGH] CVE-2016-5039: dwarfutils - The get_attr_value function in libdwarf before 20160923 allows remote attackers ... The get_attr_value function in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted object with all-bits on. Scope: local bookworm: resolved (fixed in 20160507-1) bullseye: resolved (fixed in 20160507-1) forky: resolved (fixed in 20160507-1) sid: resolved (fixed in 20160507-1) trixie: resolved (fixed in 20
debian
CVE-2016-9276P3HIGHCVSS 7.5fixed in dwarfutils 20161124-1 (bookworm)2016
CVE-2016-9276 [HIGH] CVE-2016-9276: dwarfutils - The dwarf_get_aranges_list function in dwarf_arrange.c in Libdwarf before 201611... The dwarf_get_aranges_list function in dwarf_arrange.c in Libdwarf before 20161124 allows remote attackers to cause a denial of service (out-of-bounds read). Scope: local bookworm: resolved (fixed in 20161124-1) bullseye: resolved (fixed in 20161124-1) forky: resolved (fixed in 20161124-1) sid: resolved (fixed in 20161124-1) trixie: resolved (fixed in 20161124-1)
debian
CVE-2022-34299P3HIGHCVSS 8.1fixed in dwarfutils 1:0.11.1-1 (forky)2022
CVE-2022-34299 [HIGH] CVE-2022-34299: dwarfutils - There is a heap-based buffer over-read in libdwarf 0.4.0. This issue is related ... There is a heap-based buffer over-read in libdwarf 0.4.0. This issue is related to dwarf_global_formref_b. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 1:0.11.1-1) sid: resolved (fixed in 1:0.11.1-1) trixie: resolved (fixed in 1:0.11.1-1)
debian
CVE-2024-2002P3HIGHCVSS 7.5fixed in dwarfutils 1:0.11.1-1 (forky)2024
CVE-2024-2002 [HIGH] CVE-2024-2002: dwarfutils - A double-free vulnerability was found in libdwarf. In a multiply-corrupted DWARF... A double-free vulnerability was found in libdwarf. In a multiply-corrupted DWARF object, libdwarf may try to dealloc(free) an allocation twice, potentially causing unpredictable and various results. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 1:0.11.1-1) sid: resolved (fixed in 1:0.11.1-1) trixie: resolved (fixed in 1:0.11.1-1)
debian
CVE-2016-5041P4HIGHCVSS 7.5fixed in dwarfutils 20160507-1 (bookworm)2016
CVE-2016-5041 [HIGH] CVE-2016-5041: dwarfutils - dwarf_macro5.c in libdwarf before 20160923 allows remote attackers to cause a de... dwarf_macro5.c in libdwarf before 20160923 allows remote attackers to cause a denial of service (NULL pointer dereference) via a debugging information entry using DWARF5 and without a DW_AT_name. Scope: local bookworm: resolved (fixed in 20160507-1) bullseye: resolved (fixed in 20160507-1) forky: resolved (fixed in 20160507-1) sid: resolved (fixed in 20160507-1) tr
debian
CVE-2016-5040P4HIGHCVSS 7.5fixed in dwarfutils 20160507-1 (bookworm)2016
CVE-2016-5040 [HIGH] CVE-2016-5040: dwarfutils - libdwarf before 20160923 allows remote attackers to cause a denial of service (o... libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a large length value in a compilation unit header. Scope: local bookworm: resolved (fixed in 20160507-1) bullseye: resolved (fixed in 20160507-1) forky: resolved (fixed in 20160507-1) sid: resolved (fixed in 20160507-1) trixie: resolved (fixed in 2016050
debian
CVE-2022-32200P4HIGHCVSS 7.8fixed in dwarfutils 1:0.11.1-1 (forky)2022
CVE-2022-32200 [HIGH] CVE-2022-32200: dwarfutils - libdwarf 0.4.0 has a heap-based buffer over-read in _dwarf_check_string_valid in... libdwarf 0.4.0 has a heap-based buffer over-read in _dwarf_check_string_valid in dwarf_util.c. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 1:0.11.1-1) sid: resolved (fixed in 1:0.11.1-1) trixie: resolved (fixed in 1:0.11.1-1)
debian
CVE-2016-2050P4LOWCVSS 6.5fixed in dwarfutils 20160507+git20160523.9086738-1 (bookworm)2016
CVE-2016-2050 [MEDIUM] CVE-2016-2050: dwarfutils - The get_abbrev_array_info function in libdwarf-20151114 allows remote attackers ... The get_abbrev_array_info function in libdwarf-20151114 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted elf file. Scope: local bookworm: resolved (fixed in 20160507+git20160523.9086738-1) bullseye: resolved (fixed in 20160507+git20160523.9086738-1) forky: resolved (fixed in 20160507+git20160523.9086738-1) sid: resolved (fi
debian
Debian Dwarfutils vulnerabilities | cvebase