CVE-2016-8390
An exploitable out of bounds write vulnerability exists in the parsing of ELF Section Headers of Hopper Disassembler 3.11.20.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.23%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An exploitable out of bounds write vulnerability exists in the parsing of ELF Section Headers of Hopper Disassembler 3.11.20. A specially crafted ELF file can cause attacker controlled pointer arithmetic resulting in a partially controlled out of bounds write. An attacker can craft an ELF file with specific section headers to trigger this vulnerability.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 1.23% probability · 67th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-787
- Affected
- cryptic-apps/hopper disassembler
- Source
- talos-cna@cisco.com
References
- http://www.securityfocus.com/bid/93801Broken Link, Third Party Advisory, VDB Entry
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2016-0222Third Party Advisory
- http://www.securityfocus.com/bid/93801Broken Link, Third Party Advisory, VDB Entry
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2016-0222Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.