Executive brief
LIEF is a library for parsing and manipulating executable file formats. A null pointer dereference in the ELF core file parsing component can cause the application to crash when processing malformed or specially crafted ELF files, leading to denial of service for any tool or service that uses LIEF to analyze binaries.
Technical details
LIEF contains a null pointer dereference (CWE-476) in CoreFile.tcc:69 when parsing ELF core files. The vulnerability occurs during the assignment of a string object in the CoreFile::parse_() template function, triggered by malformed ELF headers or missing program headers. An attacker can trigger a segmentation fault by providing a specially crafted ELF binary file. The vulnerability is reachable via file input with no authentication required, but requires user interaction (loading the malicious file). A patch is available in commit ca938740264f1fcb18f91cba8e4039c518ecb75b.
Affected products
- LIEF LIEF 0.8.0 through 0.12.1
Timeline
- 2022-09-14: disclosed
- 2022-09-20: patched: Fix available in commit ca938740264f1fcb18f91cba8e4039c518ecb75b