PT-2018-3616 · Red Hat+5 · Elfutils+6

Wcventure

·

Published

2018-10-17

·

Updated

2023-08-30

·

CVE-2018-18521

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions elfutils version 0.174
Description The issue is related to a divide-by-zero vulnerability in the arlib add symbols() function in arlib.c in elfutils. This vulnerability can be exploited by remote attackers to cause a denial of service, resulting in an application crash, by using a crafted ELF file. The vulnerability is caused by the mishandling of a zero sh entsize.
Recommendations For elfutils version 0.174, consider updating to a newer version that addresses this issue, as the current version is affected by the divide-by-zero vulnerability in the arlib add symbols() function.

Exploit

Fix

DoS

Divide By Zero

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2658
BDU:2021-01385
CESA-2019_2197
CVE-2018-18521
DLA-1689-1
DLA-2802-1
MGASA-2019-0222
OPENSUSE-SU-2019:1590-1
OPENSUSE-SU-2019_1590-1
OPENSUSE-SU-2022_2614-1
RHSA-2019:2197
RHSA-2019_2197
SUSE-SU-2019:1486-1
SUSE-SU-2019:1733-1
SUSE-SU-2019_1486-1
SUSE-SU-2022:2614-1
SUSE-SU-2022:2614-2
USN-4012-1
USN-6322-1

Affected Products

Alt Linux
Centos
Linuxmint
Red Hat
Suse
Ubuntu
Elfutils