Source: dwarfutils
X-Debbugs-CC: t...@security.debian.org
Severity: important
Tags: security

Hi,

The following vulnerability was published for dwarfutils.

CVE-2022-32200[0]:
| libdwarf 0.4.0 has a heap-based buffer over-read in
| _dwarf_check_string_valid in dwarf_util.c.

https://github.com/davea42/libdwarf-code/issues/116
https://www.prevanders.net/dwarfbug.html#DW202205-001
        
Fixed by: 
https://github.com/davea42/libdwarf-code/commit/8151575a6ace77d005ca5bb5d71c1bfdba3f7069

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2022-32200
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-32200

Please adjust the affected versions in the BTS as needed.

Reply via email to