Vulnerability Description
libdwarf before 20201201 allows a dwarf_print_lines.c NULL pointer dereference and application crash via a DWARF5 line-table header that has an invalid FORM for a pathname.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Libdwarf Project | Libdwarf | < 2020-12-01 |
Related Weaknesses (CWE)
References
- http://web.archive.org/web/20190601140703/https://sourceforge.net/projects/libdwProduct
- https://bugzilla.redhat.com/show_bug.cgi?id=2026000Issue TrackingPermissions RequiredThird Party Advisory
- https://github.com/davea42/libdwarf-code/commit/faf99408e3f9f706fc3809dd400e831fPatch
- https://www.prevanders.net/dwarfbug.html#DW202010-003Third Party Advisory
- http://web.archive.org/web/20190601140703/https://sourceforge.net/projects/libdwProduct
- https://bugzilla.redhat.com/show_bug.cgi?id=2026000Issue TrackingPermissions RequiredThird Party Advisory
- https://github.com/davea42/libdwarf-code/commit/faf99408e3f9f706fc3809dd400e831fPatch
- https://www.prevanders.net/dwarfbug.html#DW202010-003Third Party Advisory
FAQ
What is CVE-2020-28163?
CVE-2020-28163 is a vulnerability with a CVSS score of 6.5 (MEDIUM). libdwarf before 20201201 allows a dwarf_print_lines.c NULL pointer dereference and application crash via a DWARF5 line-table header that has an invalid FORM for a pathname.
How severe is CVE-2020-28163?
CVE-2020-28163 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-28163?
Check the references section above for vendor advisories and patch information. Affected products include: Libdwarf Project Libdwarf.