9.8
CVSSv3

CVE-2017-9055

Published: 18/05/2017 Updated: 01/03/2022
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

An issue, also known as DW201703-001, exists in libdwarf 2017-03-21. In dwarf_formsdata() a few data types were not checked for being in bounds, leading to a heap-based buffer over-read.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

libdwarf project libdwarf 2017-03-21

Vendor Advisories

Debian Bug report logs - #866968 dwarfutils: CVE-2017-9998: SEGV libdwarf/dwarf_lebc:291 in _dwarf_decode_s_leb128_chk Package: src:dwarfutils; Maintainer for src:dwarfutils is Fabian Wolff <fabiwolff@arcorde>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 3 Jul 2017 05:09:01 UTC Severity: norm ...
Debian Bug report logs - #864064 CVE-2017-9055 CVE-2017-9054 CVE-2017-9053 CVE-2017-9052 Package: src:dwarfutils; Maintainer for src:dwarfutils is Fabian Wolff <fabiwolff@arcorde>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Sat, 3 Jun 2017 21:06:01 UTC Severity: important Tags: security, upstream Foun ...