Junglewise Threat Intelligence

CVE-2024-31636: LIEF uninitialized variable in machd_reader.c

CVE-2024-31636 · Severity: low · CVSS 3.9 · Published 2024-05-03

Technologies: Lief-Project Lief. Vendors: PyPI.

Executive brief

LIEF is a library used by developers and security researchers to analyze and modify executable files. A vulnerability in version 0.14.1 could allow a local attacker to access sensitive information or cause the software to crash when processing specially crafted files. This could lead to minor data exposure or disruption of automated analysis tools.

Technical details

A Use of Uninitialized Variable (CWE-457) exists in LIEF v0.14.1 within the `machd_reader.c` component. Specifically, the `binary->name` parameter is not properly initialized during the parsing of Mach-O files. A local attacker can exploit this by providing a malformed file, which may cause the program to crash or leak contents of memory (random printing of data) when the uninitialized pointer is accessed. The issue is triggered during the execution of `macho_parse` and subsequent calls to `print_binary`. This vulnerability was addressed in version 0.15.0.

Affected products

  • lief-project LIEF < 0.15.0

Timeline

  • 2024-03-29: disclosed: Issue reported on GitHub repository
  • 2024-05-03: advisory: CVE-2024-31636 published
  • 2024-05-03: patched: GitHub Advisory published and version 0.15.0 released

References

Related threats