Vulnerability Description
libdwarf before 20201017 has a one-byte out-of-bounds read because of an invalid pointer dereference via an invalid line table in a crafted object.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Libdwarf Project | Libdwarf | < 2020-10-17 |
Related Weaknesses (CWE)
References
- http://web.archive.org/web/20190601140703/https://sourceforge.net/projects/libdwProduct
- https://bugzilla.redhat.com/show_bug.cgi?id=2025694Issue TrackingPermissions RequiredThird Party Advisory
- https://github.com/davea42/libdwarf-code/commit/95f634808c01f1c61bbec56ed2395af9Patch
- https://sourceforge.net/projects/libdwarf/Product
- https://www.prevanders.net/dwarfbug.html#DW202010-001Third Party Advisory
- http://web.archive.org/web/20190601140703/https://sourceforge.net/projects/libdwProduct
- https://bugzilla.redhat.com/show_bug.cgi?id=2025694Issue TrackingPermissions RequiredThird Party Advisory
- https://github.com/davea42/libdwarf-code/commit/95f634808c01f1c61bbec56ed2395af9Patch
- https://sourceforge.net/projects/libdwarf/Product
- https://www.prevanders.net/dwarfbug.html#DW202010-001Third Party Advisory
FAQ
What is CVE-2020-27545?
CVE-2020-27545 is a vulnerability with a CVSS score of 6.5 (MEDIUM). libdwarf before 20201017 has a one-byte out-of-bounds read because of an invalid pointer dereference via an invalid line table in a crafted object.
How severe is CVE-2020-27545?
CVE-2020-27545 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-27545?
Check the references section above for vendor advisories and patch information. Affected products include: Libdwarf Project Libdwarf.