CVE-2019-14249

Name
CVE-2019-14249
Description
dwarf_elf_load_headers.c in libdwarf before 2019-07-05 allows attackers to cause a denial of service (division by zero) via an ELF file with a zero-size section group (SHT_GROUP), as demonstrated by dwarfdump.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Patch https://sourceforge.net/p/libdwarf/code/merge-requests/4/
Patch https://sourceforge.net/p/libdwarf/code/ci/cb7198abde46c2ae29957ad460da6886eaa606ba/tree/libdwarf/dwarf_elf_load_headers.c?diff=99e77c3894877a1dd80b82808d8309eded4e5599
Third Party Advisory http://www.securityfocus.com/bid/109380

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:libdwarf_project:libdwarf:*:*:*:*:*:*:*:* libdwarf >= None < 2019-07-05

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
libdwarf 3.18-main 0.6.0-r2 Natanael Copa <ncopa@alpinelinux.org> fixed
libdwarf 3.19-main 0.8.0-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
libdwarf edge-main 0.9.2-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
libdwarf 3.20-main 0.9.2-r0 Natanael Copa <ncopa@alpinelinux.org> fixed