Junglewise Threat Intelligence

CVE-2021-32297: PYSEC-2021-324 - An issue was discovered in LIEF through 0.11.4. A heap-buffer-overflow exists in the function main located in pe_reader.c. It allows an atta

CVE-2021-32297 · Severity: low · CVSS 3.1 · Published 2021-09-20

Technologies: LIEF Project Lief. Vendors: PyPI.

Executive brief

LIEF is a library used to parse and manipulate binary executable files (PE, ELF, Mach-O formats). A heap-buffer-overflow vulnerability in the PE file parser allows an attacker who provides a malformed PE file to trigger arbitrary code execution. This could affect any application or tool that uses LIEF to process untrusted executable files.

Technical details

A heap-buffer-overflow exists in LIEF's PE binary parser, specifically in the pe_reader.c component during section initialization. The vulnerability is triggered when processing a specially crafted PE file, causing a one-byte out-of-bounds read/write that can be leveraged for code execution. The attack vector requires user interaction (opening a malicious PE file), but no authentication is needed. The vulnerability affects all versions prior to 0.11.0, with the fix committed to the LIEF repository. The root cause is improper bounds checking when initializing PE sections in the C API wrapper.

Affected products

  • LIEF Project LIEF prior to 0.11.0

Timeline

  • 2021-09-20: disclosed
  • 0.11.0: patched

References

Related threats