Vulnerability Name: | CVE-2016-9558 (CCN-123646) | ||||||||||||||||||||||||||||||||||||||||||||
Assigned: | 2016-11-22 | ||||||||||||||||||||||||||||||||||||||||||||
Published: | 2017-02-28 | ||||||||||||||||||||||||||||||||||||||||||||
Updated: | 2022-03-01 | ||||||||||||||||||||||||||||||||||||||||||||
Summary: | (1) libdwarf/dwarf_leb.c and (2) dwarfdump/print_frames.c in libdwarf before 20161124 allow remote attackers to have unspecified impact via a crafted bit pattern in a signed leb number, aka a "negation overflow." | ||||||||||||||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 9.8 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) 8.5 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
6.4 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||||||||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-190 | ||||||||||||||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2016-9558 Source: CCN Type: oss-sec Mailing List, Sat, 19 Nov 2016 16:14:27 +0100 libdwarf: negation overflow in dwarf_leb.c Source: MLIST Type: Mailing List, Patch, Third Party Advisory [oss-security] 20161119 libdwarf: negation overflow in dwarf_leb.c Source: MLIST Type: Mailing List, Patch, Third Party Advisory [oss-security] 20161122 Re: libdwarf: negation overflow in dwarf_leb.c Source: BID Type: Third Party Advisory, VDB Entry 94491 Source: CCN Type: BID-94491 libdwarf CVE-2016-9558 Integer Overflow Vulnerability Source: MISC Type: Exploit, Patch, Third Party Advisory, VDB Entry https://blogs.gentoo.org/ago/2016/11/19/libdwarf-negation-overflow-in-dwarf_leb-c/ Source: XF Type: UNKNOWN libdwarf-cve20169558-bo(123646) Source: CCN Type: libdwarf GIT Repository libdwarf Source: CONFIRM Type: Third Party Advisory https://sourceforge.net/p/libdwarf/code/ci/4f19e1050cd8e9ddf2cb6caa061ff2fec4c9b5f9/#diff-5 Source: CONFIRM Type: Third Party Advisory https://www.prevanders.net/dwarfbug.html Source: CCN Type: WhiteSource Vulnerability Database CVE-2016-9558 | ||||||||||||||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||||||||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||||||
BACK |