The dwarf_get_aranges_list function in libdwarf before 20160923 allows remote attackers to cause a denial of service (infinite loop and crash) via a crafted DWARF section.
The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Libdwarf | Libdwarf_project | 1999-12-14 (including) | 2016-09-23 (excluding) |
Dwarfutils | Ubuntu | precise | * |
Dwarfutils | Ubuntu | trusty | * |
Dwarfutils | Ubuntu | upstream | * |
Dwarfutils | Ubuntu | wily | * |
Dwarfutils | Ubuntu | xenial | * |