{"id":"CVE-2016-5042","details":"The dwarf_get_aranges_list function in libdwarf before 20160923 allows remote attackers to cause a denial of service (infinite loop and crash) via a crafted DWARF section.","modified":"2026-03-12T22:21:53.070601Z","published":"2017-02-17T17:59:00.653Z","references":[{"type":"ADVISORY","url":"https://www.prevanders.net/dwarfbug.html"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1332145"},{"type":"FIX","url":"http://www.openwall.com/lists/oss-security/2016/05/24/1"},{"type":"EVIDENCE","url":"http://www.openwall.com/lists/oss-security/2016/05/25/1"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/davea42/libdwarf-code","events":[{"introduced":"0"},{"fixed":"a2b2d14bdc005a5082463d4f68c106a7044efe8c"}],"database_specific":{"versions":[{"introduced":"0"},{"fixed":"20160923"}]}}],"versions":["20110113","20110605","20110607","20110612","20110908","20111009","20111030","20111214","20120410","20121127","20121130","20130125","20130126","20130207","20130729","20130729-b","20140131","20140208","20140413","20140519","20140805","20150112","20150115","20150310","20150507","20150913","20150915","20151114","20160116","20160507","20160613"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-5042.json","unresolved_ranges":[{"events":[{"introduced":"1999-12-14"},{"fixed":"2016-09-23"}]}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}