PT-2017-3782 · Red Hat+3 · Elfutils+3
Agostino Sarubbo
·
Published
2017-04-09
·
Updated
2022-08-01
·
CVE-2017-7610
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
elfutils version 0.168
Description
The issue is related to a heap-based buffer over-read and application crash in the
check group function. This can be exploited by remote attackers via a crafted ELF file, leading to a denial of service. The vulnerability is associated with an out-of-bounds read operation in memory.Recommendations
For elfutils version 0.168, consider disabling the
check group function as a temporary workaround until a patch is available. Restrict access to crafted ELF files to minimize the risk of exploitation.Exploit
Fix
DoS
Out of bounds Read
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Suse
Ubuntu
Elfutils