Executive brief
LIEF is a library used to parse and manipulate binary executable files (PE, ELF, Mach-O formats). A heap-buffer-overflow vulnerability in the PE file parser allows an attacker who provides a malformed PE file to trigger arbitrary code execution. This could affect any application or tool that uses LIEF to process untrusted executable files.
Technical details
A heap-buffer-overflow exists in LIEF's PE binary parser, specifically in the pe_reader.c component during section initialization. The vulnerability is triggered when processing a specially crafted PE file, causing a one-byte out-of-bounds read/write that can be leveraged for code execution. The attack vector requires user interaction (opening a malicious PE file), but no authentication is needed. The vulnerability affects all versions prior to 0.11.0, with the fix committed to the LIEF repository. The root cause is improper bounds checking when initializing PE sections in the C API wrapper.
Affected products
- LIEF Project LIEF prior to 0.11.0
Timeline
- 2021-09-20: disclosed
- 0.11.0: patched