Bug 963791 (CVE-2016-2050) - VUL-1: CVE-2016-2050: libdwarf: Out-of-bounds write in get_abbrev_array_info
Summary: VUL-1: CVE-2016-2050: libdwarf: Out-of-bounds write in get_abbrev_array_info
Status: RESOLVED FIXED
Alias: CVE-2016-2050
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P4 - Low : Minor
Target Milestone: ---
Assignee: Michael Matz
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/161264/
Whiteboard: CVSSv2:SUSE:CVE-2016-2050:1.5:(AV:L/A...
Keywords:
Depends on:
Blocks:
 
Reported: 2016-01-27 14:10 UTC by Johannes Segitz
Modified: 2024-05-20 11:50 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Johannes Segitz 2016-01-27 14:10:29 UTC
rh#1300330

An out-of-bounds write vulnerability was found in libdwarf-20151114 in get_abbrev_array_info function.

CVE request (contains reproducer and valgrind report):

http://seclists.org/oss-sec/2016/q1/141

SLE 11 SP3/4 SDK and openSUSE

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1300330
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-2050
http://seclists.org/oss-sec/2016/q1/196
http://people.canonical.com/~ubuntu-security/cve/2016/CVE-2016-2050.html
Comment 1 Swamp Workflow Management 2016-01-28 23:01:37 UTC
bugbot adjusting priority