Skip to content

Commit

Permalink
Documenting DW202305-003 oss fuzz 59091
Browse files Browse the repository at this point in the history
	modified:   bugxml/data.txt
	modified:   bugxml/dwarfbug.html
	modified:   bugxml/dwarfbug.xml
	modified:   bugxml/dwarfbuglohi.html
  • Loading branch information
davea42 committed May 19, 2023
1 parent 4017ab8 commit 60e572d
Show file tree
Hide file tree
Showing 4 changed files with 260 additions and 145 deletions.
20 changes: 19 additions & 1 deletion bugxml/data.txt
Original file line number Diff line number Diff line change
@@ -1,4 +1,22 @@

id: DW202305-003
cve:
fuzzer: ossfuzz id: 59091
datereported: 2023-05-19
reportedby: David Korczynski
vulnerability: Incorrect section bound check
product: libdwarf
description: A fuzzed line table in the non-standard
(experimental) two-level line table format
exposed a failure as the test was v > sectionend
whereas it has to be v >= sectionend as end pointers
are always one-past the end of the area.
This was incorrect since the experimental table support
was added in 2021.
datefixed: 2023-05-19
references: regressiontest/ossfuzz59091/fuzz_macro_dwarf5-5135813562990592
gitfixid: 4017ab8b92195641e6876b388cebe2d3307634f5
tarrelease:
endrec: DW202305-003

id: DW202305-002
cve:
Expand Down
Loading

0 comments on commit 60e572d

Please sign in to comment.