Heap-based Buffer Over-read in libdw in elfutils 0.173

Heap-based Buffer Over-read in libdw in elfutils 0.173

CVE-2018-16403 · MEDIUM Severity

AV:N/AC:M/AU:N/C:N/I:N/A:P

libdw in elfutils 0.173 checks the end of the attributes list incorrectly in dwarf_getabbrev in dwarf_getabbrev.c and dwarf_hasattr in dwarf_hasattr.c, leading to a heap-based buffer over-read and an application crash.

Learn more about our Web Application Penetration Testing UK.