Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q33x-5cf5-cqqv

Опубликовано: 22 авг. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

The libcpu component which is used by libasm of elfutils version 0.177 (git 47780c9e), suffers from denial-of-service vulnerability caused by application crashes due to out-of-bounds write (CWE-787), off-by-one error (CWE-193) and reachable assertion (CWE-617); to exploit the vulnerability, the attackers need to craft certain ELF files which bypass the missing bound checks.

The libcpu component which is used by libasm of elfutils version 0.177 (git 47780c9e), suffers from denial-of-service vulnerability caused by application crashes due to out-of-bounds write (CWE-787), off-by-one error (CWE-193) and reachable assertion (CWE-617); to exploit the vulnerability, the attackers need to craft certain ELF files which bypass the missing bound checks.

EPSS

Процентиль: 0%
0.00005
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 2 лет назад

The libcpu component which is used by libasm of elfutils version 0.177 (git 47780c9e), suffers from denial-of-service vulnerability caused by application crashes due to out-of-bounds write (CWE-787), off-by-one error (CWE-193) and reachable assertion (CWE-617); to exploit the vulnerability, the attackers need to craft certain ELF files which bypass the missing bound checks.

CVSS3: 5.5
nvd
больше 2 лет назад

The libcpu component which is used by libasm of elfutils version 0.177 (git 47780c9e), suffers from denial-of-service vulnerability caused by application crashes due to out-of-bounds write (CWE-787), off-by-one error (CWE-193) and reachable assertion (CWE-617); to exploit the vulnerability, the attackers need to craft certain ELF files which bypass the missing bound checks.

CVSS3: 5.5
debian
больше 2 лет назад

The libcpu component which is used by libasm of elfutils version 0.177 ...

CVSS3: 5.5
fstec
больше 6 лет назад

Уязвимость компонента libcpu утилиты для модификации и анализа бинарных файлов ELF Elfutils, связанная с записью за границами буфера, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 0%
0.00005
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-787