Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2020-21047

Опубликовано: 22 авг. 2023
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 5.5

Описание

The libcpu component which is used by libasm of elfutils version 0.177 (git 47780c9e), suffers from denial-of-service vulnerability caused by application crashes due to out-of-bounds write (CWE-787), off-by-one error (CWE-193) and reachable assertion (CWE-617); to exploit the vulnerability, the attackers need to craft certain ELF files which bypass the missing bound checks.

РелизСтатусПримечание
bionic

ignored

end of standard support
devel

not-affected

0.189-4
esm-infra-legacy/trusty

released

0.158-0ubuntu5.3+esm1
esm-infra/bionic

released

0.170-0.4ubuntu0.1+esm1
esm-infra/focal

released

0.176-1.1ubuntu0.1
esm-infra/xenial

released

0.165-3ubuntu1.2+esm1
focal

released

0.176-1.1ubuntu0.1
jammy

not-affected

0.186-1build1
lunar

not-affected

0.188-2.1
trusty

ignored

end of standard support

Показывать по

EPSS

Процентиль: 0%
0.00005
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
nvd
больше 2 лет назад

The libcpu component which is used by libasm of elfutils version 0.177 (git 47780c9e), suffers from denial-of-service vulnerability caused by application crashes due to out-of-bounds write (CWE-787), off-by-one error (CWE-193) and reachable assertion (CWE-617); to exploit the vulnerability, the attackers need to craft certain ELF files which bypass the missing bound checks.

CVSS3: 5.5
debian
больше 2 лет назад

The libcpu component which is used by libasm of elfutils version 0.177 ...

CVSS3: 5.5
github
больше 2 лет назад

The libcpu component which is used by libasm of elfutils version 0.177 (git 47780c9e), suffers from denial-of-service vulnerability caused by application crashes due to out-of-bounds write (CWE-787), off-by-one error (CWE-193) and reachable assertion (CWE-617); to exploit the vulnerability, the attackers need to craft certain ELF files which bypass the missing bound checks.

CVSS3: 5.5
fstec
больше 6 лет назад

Уязвимость компонента libcpu утилиты для модификации и анализа бинарных файлов ELF Elfutils, связанная с записью за границами буфера, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 0%
0.00005
Низкий

5.5 Medium

CVSS3