dwarfelfloadheaders.c in libdwarf before 2019-07-05 allows attackers to cause a denial of service (division by zero) via an ELF file with a zero-size section group (SHTGROUP), as demonstrated by dwarfdump.
{ "binaries": [ { "binary_version": "20210528-1", "binary_name": "dwarfdump" }, { "binary_version": "20210528-1", "binary_name": "dwarfdump-dbgsym" }, { "binary_version": "20210528-1", "binary_name": "libdwarf-dev" }, { "binary_version": "20210528-1", "binary_name": "libdwarf1" }, { "binary_version": "20210528-1", "binary_name": "libdwarf1-dbgsym" } ], "availability": "No subscription required" }
{ "binaries": [ { "binary_version": "20210528-1build2", "binary_name": "dwarfdump" }, { "binary_version": "20210528-1build2", "binary_name": "dwarfdump-dbgsym" }, { "binary_version": "20210528-1build2", "binary_name": "libdwarf-dev" }, { "binary_version": "20210528-1build2", "binary_name": "libdwarf1" }, { "binary_version": "20210528-1build2", "binary_name": "libdwarf1-dbgsym" } ], "availability": "No subscription required" }
{ "binaries": [ { "binary_version": "20210528-1build2", "binary_name": "dwarfdump" }, { "binary_version": "20210528-1build2", "binary_name": "dwarfdump-dbgsym" }, { "binary_version": "20210528-1build2", "binary_name": "libdwarf-dev" }, { "binary_version": "20210528-1build2", "binary_name": "libdwarf1" }, { "binary_version": "20210528-1build2", "binary_name": "libdwarf1-dbgsym" } ], "availability": "No subscription required" }