Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-7665

Опубликовано: 09 фев. 2019
Источник: debian
EPSS Низкий

Описание

In elfutils 0.175, a heap-based buffer over-read was discovered in the function elf32_xlatetom in elf32_xlatetom.c in libelf. A crafted ELF input can cause a segmentation fault leading to denial of service (program crash) because ebl_core_note does not reject malformed core file notes.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
elfutilsfixed0.176-1package

Примечания

  • https://sourceware.org/bugzilla/show_bug.cgi?id=24089

  • https://sourceware.org/ml/elfutils-devel/2019-q1/msg00049.html

  • https://sourceware.org/git/?p=elfutils.git;a=commit;h=de01cc6f9446187d69b9748bb3636361c79e77a4

EPSS

Процентиль: 34%
0.00141
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 7 лет назад

In elfutils 0.175, a heap-based buffer over-read was discovered in the function elf32_xlatetom in elf32_xlatetom.c in libelf. A crafted ELF input can cause a segmentation fault leading to denial of service (program crash) because ebl_core_note does not reject malformed core file notes.

CVSS3: 3.3
redhat
около 7 лет назад

In elfutils 0.175, a heap-based buffer over-read was discovered in the function elf32_xlatetom in elf32_xlatetom.c in libelf. A crafted ELF input can cause a segmentation fault leading to denial of service (program crash) because ebl_core_note does not reject malformed core file notes.

CVSS3: 5.5
nvd
почти 7 лет назад

In elfutils 0.175, a heap-based buffer over-read was discovered in the function elf32_xlatetom in elf32_xlatetom.c in libelf. A crafted ELF input can cause a segmentation fault leading to denial of service (program crash) because ebl_core_note does not reject malformed core file notes.

CVSS3: 5.5
github
больше 3 лет назад

In elfutils 0.175, a heap-based buffer over-read was discovered in the function elf32_xlatetom in elf32_xlatetom.c in libelf. A crafted ELF input can cause a segmentation fault leading to denial of service (program crash) because ebl_core_note does not reject malformed core file notes.

CVSS3: 5.5
fstec
почти 7 лет назад

Уязвимость функции elf32_xlatetom в пакете elfutils, связанная с возможностью выхода операции за границы буфера в памяти, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 34%
0.00141
Низкий