dwarfelfloadheaders.c in libdwarf before 2019-07-05 allows attackers to cause a denial of service (division by zero) via an ELF file with a zero-size section group (SHTGROUP), as demonstrated by dwarfdump.
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "dwarfdump",
"binary_version": "20210528-1"
},
{
"binary_name": "dwarfdump-dbgsym",
"binary_version": "20210528-1"
},
{
"binary_name": "libdwarf-dev",
"binary_version": "20210528-1"
},
{
"binary_name": "libdwarf1",
"binary_version": "20210528-1"
},
{
"binary_name": "libdwarf1-dbgsym",
"binary_version": "20210528-1"
}
]
}
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "dwarfdump",
"binary_version": "20210528-1build2"
},
{
"binary_name": "dwarfdump-dbgsym",
"binary_version": "20210528-1build2"
},
{
"binary_name": "libdwarf-dev",
"binary_version": "20210528-1build2"
},
{
"binary_name": "libdwarf1",
"binary_version": "20210528-1build2"
},
{
"binary_name": "libdwarf1-dbgsym",
"binary_version": "20210528-1build2"
}
]
}
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "dwarfdump",
"binary_version": "20210528-1build2"
},
{
"binary_name": "dwarfdump-dbgsym",
"binary_version": "20210528-1build2"
},
{
"binary_name": "libdwarf-dev",
"binary_version": "20210528-1build2"
},
{
"binary_name": "libdwarf1",
"binary_version": "20210528-1build2"
},
{
"binary_name": "libdwarf1-dbgsym",
"binary_version": "20210528-1build2"
}
]
}