Skip to content

Commit 60e572d

Browse files
committed
Documenting DW202305-003 oss fuzz 59091
modified: bugxml/data.txt modified: bugxml/dwarfbug.html modified: bugxml/dwarfbug.xml modified: bugxml/dwarfbuglohi.html
1 parent 4017ab8 commit 60e572d

File tree

4 files changed

+260
-145
lines changed

4 files changed

+260
-145
lines changed

bugxml/data.txt

Lines changed: 19 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,22 @@
1-
1+
id: DW202305-003
2+
cve:
3+
fuzzer: ossfuzz id: 59091
4+
datereported: 2023-05-19
5+
reportedby: David Korczynski
6+
vulnerability: Incorrect section bound check
7+
product: libdwarf
8+
description: A fuzzed line table in the non-standard
9+
(experimental) two-level line table format
10+
exposed a failure as the test was v > sectionend
11+
whereas it has to be v >= sectionend as end pointers
12+
are always one-past the end of the area.
13+
This was incorrect since the experimental table support
14+
was added in 2021.
15+
datefixed: 2023-05-19
16+
references: regressiontest/ossfuzz59091/fuzz_macro_dwarf5-5135813562990592
17+
gitfixid: 4017ab8b92195641e6876b388cebe2d3307634f5
18+
tarrelease:
19+
endrec: DW202305-003
220

321
id: DW202305-002
422
cve:

0 commit comments

Comments
 (0)