PT-2019-6429 · Red Hat+3 · Elfutils+3
Leftcopy.Chx
·
Publicado
2019-10-06
·
Atualizado
2023-09-23
·
CVE-2020-21047
CVSS v3.1
5.5
Média
| Vetor | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
elfutils version 0.177
Description
The issue is related to a denial-of-service vulnerability in the libcpu component of elfutils, caused by application crashes due to out-of-bounds write, off-by-one error, and reachable assertion. Attackers can exploit this by crafting certain ELF files that bypass missing bound checks.
Recommendations
For elfutils version 0.177, consider updating to a newer version that addresses the out-of-bounds write, off-by-one error, and reachable assertion issues to prevent application crashes and potential denial-of-service attacks. As a temporary workaround, restrict the use of specially crafted ELF files that could exploit the vulnerability.
Correção
DoS
Memory Corruption
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Astra Linux
Linuxmint
Ubuntu
Elfutils