{"id":"CVE-2016-9275","details":"Heap-based buffer overflow in the _dwarf_skim_forms function in libdwarf/dwarf_macro5.c in Libdwarf before 20161124 allows remote attackers to cause a denial of service (out-of-bounds read).","modified":"2026-05-18T05:48:47.945467800Z","published":"2017-03-23T18:59:00.490Z","database_specific":{"unresolved_ranges":[{"extracted_events":[{"introduced":"1999-12-14"},{"fixed":"2016-11-24"}],"vendor_product":"libdwarf_project:libdwarf","source":"CPE_FIELD","cpes":["cpe:2.3:a:libdwarf_project:libdwarf:*:*:*:*:*:*:*:*"]}]},"references":[{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/94284"},{"type":"FIX","url":"http://www.openwall.com/lists/oss-security/2016/11/11/7"},{"type":"FIX","url":"https://blogs.gentoo.org/ago/2016/11/07/libdwarf-heap-based-buffer-overflow-in-_dwarf_skim_forms-dwarf_macro5-c"},{"type":"FIX","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1394802"},{"type":"FIX","url":"https://sourceforge.net/p/libdwarf/code/ci/583f8834083b5ef834c497f5b47797e16101a9a6/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/davea42/libdwarf-code","events":[{"introduced":"0"},{"fixed":"fd1d490f0815994a870744d99660ed72585f3741"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"20161124"}],"source":"DESCRIPTION"}}],"versions":["20161021","20161001","20160929","20160923","20160613","20160507","20160116","20151114","20150915","20150913","20150507","20150310","20150115","20150112","20140805","20140519","20140413","20140208","20140131","20130729-b","20130729","20130207","20130126","20130125","20121130","20121127","20120410","20111214","20111030","20111009","20110908","20110612","20110607","20110605","20110113"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-9275.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}