CVE-2016-8681 describes an out-of-bounds read vulnerability in the _dwarf_get_abbrev_for_code function of libdwarf versions 20161001 and earlier. This flaw can be triggered by processing a specially crafted file with the dwarfdump command, leading to a denial of service. It carries a CVSS v3.1 score of 5.5 (Medium), indicating a local attack vector with low complexity and user interaction required, ultimately resulting in high availability impact. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2016-10-01CPE matchmatch criteria | cpe:2.3:a:libdwarf_project:libdwarf:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
The _dwarf_get_abbrev_for_code function in dwarf_util.c in libdwarf 20161001 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) by calling the dwarfdump command on a crafted file.
Feb 21, 2017libdwarf: Heap based buffer overflow in _dwarf_get_abbrev_for_code
Oct 6, 2016