Vulnerability Bulletins

IBM Security Bulletin: OpenSource GNU libunwind Vulnerability affects IBM Security Guardium (CVE-2015-3239)

   
Affected software IBM
 
libunwind is vulnerable to a heap-based buffer overflow, caused by an off-by-one error in the dwarf_to_unw_regnum function in include/dwarf_i.h . commands. A local attacker could overflow a buffer and cause a denial of service or execute arbitrary code on the system. CVE(s): CVE-2015-3239Affected product(s) and affected version(s):IBM Security Guardium 9.x, 10 Refer to the following reference URLs for remediation and additional vulnerability details:Source Bulletin:

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_opensource_gnu_libunwind_vulnerability_affects_ibm_security_guardium_cve_2015_3239?lang=en_us