Executive brief
LIEF is a library used by developers and security researchers to analyze and modify executable files. A vulnerability in version 0.14.1 could allow a local attacker to access sensitive information or cause the software to crash when processing specially crafted files. This could lead to minor data exposure or disruption of automated analysis tools.
Technical details
A Use of Uninitialized Variable (CWE-457) exists in LIEF v0.14.1 within the `machd_reader.c` component. Specifically, the `binary->name` parameter is not properly initialized during the parsing of Mach-O files. A local attacker can exploit this by providing a malformed file, which may cause the program to crash or leak contents of memory (random printing of data) when the uninitialized pointer is accessed. The issue is triggered during the execution of `macho_parse` and subsequent calls to `print_binary`. This vulnerability was addressed in version 0.15.0.
Affected products
- lief-project LIEF < 0.15.0
Timeline
- 2024-03-29: disclosed: Issue reported on GitHub repository
- 2024-05-03: advisory: CVE-2024-31636 published
- 2024-05-03: patched: GitHub Advisory published and version 0.15.0 released