Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-18521

Опубликовано: 19 окт. 2018
Источник: debian
EPSS Низкий

Описание

Divide-by-zero vulnerabilities in the function arlib_add_symbols() in arlib.c in elfutils 0.174 allow remote attackers to cause a denial of service (application crash) with a crafted ELF file, as demonstrated by eu-ranlib, because a zero sh_entsize is mishandled.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
elfutilsfixed0.175-1package

Примечания

  • https://sourceware.org/bugzilla/show_bug.cgi?id=23786

  • https://sourceware.org/ml/elfutils-devel/2018-q4/msg00055.html

  • https://sourceware.org/git/?p=elfutils.git;a=commit;h=2b16a9be69939822dcafe075413468daac98b327

EPSS

Процентиль: 29%
0.00105
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 7 лет назад

Divide-by-zero vulnerabilities in the function arlib_add_symbols() in arlib.c in elfutils 0.174 allow remote attackers to cause a denial of service (application crash) with a crafted ELF file, as demonstrated by eu-ranlib, because a zero sh_entsize is mishandled.

CVSS3: 3.3
redhat
больше 7 лет назад

Divide-by-zero vulnerabilities in the function arlib_add_symbols() in arlib.c in elfutils 0.174 allow remote attackers to cause a denial of service (application crash) with a crafted ELF file, as demonstrated by eu-ranlib, because a zero sh_entsize is mishandled.

CVSS3: 5.5
nvd
больше 7 лет назад

Divide-by-zero vulnerabilities in the function arlib_add_symbols() in arlib.c in elfutils 0.174 allow remote attackers to cause a denial of service (application crash) with a crafted ELF file, as demonstrated by eu-ranlib, because a zero sh_entsize is mishandled.

CVSS3: 5.5
github
больше 3 лет назад

Divide-by-zero vulnerabilities in the function arlib_add_symbols() in arlib.c in elfutils 0.174 allow remote attackers to cause a denial of service (application crash) with a crafted ELF file, as demonstrated by eu-ranlib, because a zero sh_entsize is mishandled.

CVSS3: 6.5
fstec
больше 7 лет назад

Уязвимость функции arlib_add_symbols() файла arlib.c набора утилит для обработки объектов ELF Elfutils, связанная с делением на ноль, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 29%
0.00105
Низкий