Out-of-bounds read in libdwarf - CVE-2020-27545

 

Out-of-bounds read in libdwarf - CVE-2020-27545

Published: July 5, 2023


Vulnerability identifier: #VU78001
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-27545
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a one-byte out-of-bounds read. A remote attacker can pass specially crafted input to the application, trigger an out-of-bounds read error and perform a denial of service (DoS) attack.


Affected software

libdwarf
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Package Hub 15
openSUSE Leap
libdwarf-doc
libdwarf1-debuginfo
libdwarf-devel-debuginfo
libdwarf-tools-debuginfo
libdwarf1
libdwarf-debuginfo
libdwarf-devel-static
libdwarf-debugsource
libdwarf-devel
libdwarf-tools

How to mitigate CVE-2020-27545

Install updates from vendor's website.

libdwarf - update to 20201020
libdwarf-doc - update to 20161124-150000.3.6.1
libdwarf1-debuginfo - update to 20161124-150000.3.6.1
libdwarf-devel-debuginfo - update to 20161124-150000.3.6.1
libdwarf-tools-debuginfo - update to 20161124-150000.3.6.1
libdwarf1 - update to 20161124-150000.3.6.1
libdwarf-debuginfo - update to 20161124-150000.3.6.1
libdwarf-devel-static - update to 20161124-150000.3.6.1
libdwarf-debugsource - update to 20161124-150000.3.6.1
libdwarf-devel - update to 20161124-150000.3.6.1
libdwarf-tools - update to 20161124-150000.3.6.1

External References

Related Security Bulletins