Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-1377

Опубликовано: 17 фев. 2025
Источник: redhat
CVSS3: 3.3
EPSS Низкий

Описание

A vulnerability, which was classified as problematic, has been found in GNU elfutils 0.192. This issue affects the function gelf_getsymshndx of the file strip.c of the component eu-strip. The manipulation leads to denial of service. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The identifier of the patch is fbf1df9ca286de3323ae541973b08449f8d03aba. It is recommended to apply a patch to fix this issue.

A flaw was found in GNU elfutils. This vulnerability allows denial of service via manipulation of the gelf_getsymshndx function in strip.c.

Отчет

This vulnerability is rated Low for Red Hat Enterprise Linux 9 and 10 because it requires local access to trigger an application level denial of service in the eu-strip utility of elfutils. Other Red Hat products, including Red Hat Developer Toolset, OpenShift Container Platform, and Red Hat In-Vehicle OS, are not affected.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10elfutilsFix deferred
Red Hat Enterprise Linux 6elfutilsNot affected
Red Hat Enterprise Linux 7elfutilsNot affected
Red Hat Enterprise Linux 8elfutilsNot affected
Red Hat Enterprise Linux 9elfutilsFix deferred
Red Hat OpenShift Container Platform 4rhcosNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-404
https://bugzilla.redhat.com/show_bug.cgi?id=2346066elfutils: GNU elfutils eu-strip strip.c gelf_getsymshndx denial of service

EPSS

Процентиль: 1%
0.00011
Низкий

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 3.3
ubuntu
около 1 года назад

A vulnerability, which was classified as problematic, has been found in GNU elfutils 0.192. This issue affects the function gelf_getsymshndx of the file strip.c of the component eu-strip. The manipulation leads to denial of service. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The identifier of the patch is fbf1df9ca286de3323ae541973b08449f8d03aba. It is recommended to apply a patch to fix this issue.

CVSS3: 3.3
nvd
около 1 года назад

A vulnerability, which was classified as problematic, has been found in GNU elfutils 0.192. This issue affects the function gelf_getsymshndx of the file strip.c of the component eu-strip. The manipulation leads to denial of service. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The identifier of the patch is fbf1df9ca286de3323ae541973b08449f8d03aba. It is recommended to apply a patch to fix this issue.

CVSS3: 3.3
msrc
12 месяцев назад

GNU elfutils eu-strip strip.c gelf_getsymshndx denial of service

CVSS3: 3.3
debian
около 1 года назад

A vulnerability, which was classified as problematic, has been found i ...

CVSS3: 3.3
github
около 1 года назад

A vulnerability, which was classified as problematic, has been found in GNU elfutils 0.192. This issue affects the function gelf_getsymshndx of the file strip.c of the component eu-strip. The manipulation leads to denial of service. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The identifier of the patch is fbf1df9ca286de3323ae541973b08449f8d03aba. It is recommended to apply a patch to fix this issue.

EPSS

Процентиль: 1%
0.00011
Низкий

3.3 Low

CVSS3