The dwarfgetsizeofval function in libdwarf/dwarfutil.c in Libdwarf before 20161124 allows remote attackers to cause a denial of service (out-of-bounds read) by calling the dwarfdump command on a crafted file.
{ "binaries": [ { "binary_version": "20120410-2+deb7u2build0.16.04.1", "binary_name": "dwarfdump" }, { "binary_version": "20120410-2+deb7u2build0.16.04.1", "binary_name": "libdwarf-dev" } ] }