The afgetpage() function in lib/afflib_pages.cpp in AFFLIB (aka AFFLIBv3) through 3.7.16 allows remote attackers to cause a denial of service (segmentation fault) via a corrupt AFF image that triggers an unexpected pagesize value.
{
"binaries": [
{
"binary_version": "3.7.7-3ubuntu0.1~esm1",
"binary_name": "afflib-tools"
},
{
"binary_version": "3.7.7-3ubuntu0.1~esm1",
"binary_name": "libafflib-dev"
},
{
"binary_version": "3.7.7-3ubuntu0.1~esm1",
"binary_name": "libafflib0v5"
}
],
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro"
}
{
"binaries": [
{
"binary_version": "3.7.16-2ubuntu0.1~esm1",
"binary_name": "afflib-tools"
},
{
"binary_version": "3.7.16-2ubuntu0.1~esm1",
"binary_name": "libafflib-dev"
},
{
"binary_version": "3.7.16-2ubuntu0.1~esm1",
"binary_name": "libafflib0v5"
}
],
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro"
}