Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-16402

Опубликовано: 15 авг. 2018
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

libelf/elf_end.c in elfutils 0.173 allows remote attackers to cause a denial of service (double free and application crash) or possibly have unspecified other impact because it tries to decompress twice.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5elfutilsNot affected
Red Hat Enterprise Linux 6elfutilsNot affected
Red Hat Enterprise Linux 8elfutilsNot affected
Red Hat Virtualization 4elfutilsWill not fix
Red Hat Ansible Tower 3.4 for RHEL 7ansible-tower-34/ansible-tower-memcachedFixedRHBA-2020:054718.02.2020
Red Hat Ansible Tower 3.4 for RHEL 7ansible-tower-35/ansible-tower-memcachedFixedRHBA-2020:054718.02.2020
Red Hat Ansible Tower 3.4 for RHEL 7ansible-tower-37/ansible-tower-memcached-rhel7FixedRHBA-2020:054718.02.2020
Red Hat Enterprise Linux 7elfutilsFixedRHSA-2019:219706.08.2019
Red Hat Enterprise Linux 7.6 Extended Update SupportelfutilsFixedRHSA-2020:147114.04.2020

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=1625050elfutils: Double-free due to double decompression of sections in crafted ELF causes crash

EPSS

Процентиль: 89%
0.03691
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 8 лет назад

libelf/elf_end.c in elfutils 0.173 allows remote attackers to cause a denial of service (double free and application crash) or possibly have unspecified other impact because it tries to decompress twice.

CVSS3: 9.8
nvd
почти 8 лет назад

libelf/elf_end.c in elfutils 0.173 allows remote attackers to cause a denial of service (double free and application crash) or possibly have unspecified other impact because it tries to decompress twice.

CVSS3: 9.8
debian
почти 8 лет назад

libelf/elf_end.c in elfutils 0.173 allows remote attackers to cause a ...

CVSS3: 9.8
github
около 4 лет назад

libelf/elf_end.c in elfutils 0.173 allows remote attackers to cause a denial of service (double free and application crash) or possibly have unspecified other impact because it tries to decompress twice.

CVSS3: 9.8
fstec
почти 8 лет назад

Уязвимость компонента libelf/elf_end.c утилиты для модификации и анализа бинарных файлов ELF Elfutils, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

EPSS

Процентиль: 89%
0.03691
Низкий

4.3 Medium

CVSS3