CVE-2017-9998 describes a denial-of-service vulnerability in the libdwarf library, specifically within the _dwarf_decode_s_leb128_chk function. An unauthenticated remote attacker can trigger a segmentation fault by providing a specially crafted file, leading to system unavailability. This medium-severity vulnerability has no known public exploits, Metasploit modules, or Nuclei templates, and has received minimal community discussion or media coverage, suggesting low active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1999-12-14, <= 2017-06-28CPE matchmatch criteria | cpe:2.3:a:libdwarf_project:libdwarf:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.