Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2019-7665

Опубликовано: 09 фев. 2019
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 4.3
CVSS3: 5.5

Описание

In elfutils 0.175, a heap-based buffer over-read was discovered in the function elf32_xlatetom in elf32_xlatetom.c in libelf. A crafted ELF input can cause a segmentation fault leading to denial of service (program crash) because ebl_core_note does not reject malformed core file notes.

РелизСтатусПримечание
bionic

released

0.170-0.4ubuntu0.1
cosmic

released

0.170-0.5.0ubuntu1.1
devel

not-affected

0.176-1.1
disco

not-affected

0.176-1
eoan

not-affected

0.176-1.1
esm-infra-legacy/trusty

released

0.158-0ubuntu5.3+esm1
esm-infra/bionic

released

0.170-0.4ubuntu0.1
esm-infra/focal

not-affected

0.176-1.1
esm-infra/xenial

released

0.165-3ubuntu1.2
focal

not-affected

0.176-1.1

Показывать по

EPSS

Процентиль: 34%
0.00141
Низкий

4.3 Medium

CVSS2

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 3.3
redhat
около 7 лет назад

In elfutils 0.175, a heap-based buffer over-read was discovered in the function elf32_xlatetom in elf32_xlatetom.c in libelf. A crafted ELF input can cause a segmentation fault leading to denial of service (program crash) because ebl_core_note does not reject malformed core file notes.

CVSS3: 5.5
nvd
почти 7 лет назад

In elfutils 0.175, a heap-based buffer over-read was discovered in the function elf32_xlatetom in elf32_xlatetom.c in libelf. A crafted ELF input can cause a segmentation fault leading to denial of service (program crash) because ebl_core_note does not reject malformed core file notes.

CVSS3: 5.5
debian
почти 7 лет назад

In elfutils 0.175, a heap-based buffer over-read was discovered in the ...

CVSS3: 5.5
github
больше 3 лет назад

In elfutils 0.175, a heap-based buffer over-read was discovered in the function elf32_xlatetom in elf32_xlatetom.c in libelf. A crafted ELF input can cause a segmentation fault leading to denial of service (program crash) because ebl_core_note does not reject malformed core file notes.

CVSS3: 5.5
fstec
почти 7 лет назад

Уязвимость функции elf32_xlatetom в пакете elfutils, связанная с возможностью выхода операции за границы буфера в памяти, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 34%
0.00141
Низкий

4.3 Medium

CVSS2

5.5 Medium

CVSS3