PT-2018-3828 · Red Hat+4 · Elfutils+5

Wcventure

·

Published

2018-08-15

·

Updated

2022-08-01

·

CVE-2018-16402

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions elfutils version 0.173
Description The issue is related to a double free error in the libelf/elf end.c component of the elfutils utility, which is used for modifying and analyzing ELF binary files. This error can be exploited by a remote attacker to gain access to confidential data, compromise data integrity, and cause a denial of service. The vulnerability occurs because the component attempts to decompress data twice.
Recommendations For elfutils version 0.173, consider applying a patch or updating to a newer version that fixes the double free error in the libelf/elf end.c component to prevent exploitation. As a temporary workaround, consider restricting access to the elfutils utility until a patch is available.

Exploit

Fix

DoS

Double Free

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2328
BDU:2022-05869
CESA-2019_2197
CVE-2018-16402
DLA-2802-1
MGASA-2019-0222
OPENSUSE-SU-2019:1590-1
OPENSUSE-SU-2019_1590-1
OPENSUSE-SU-2022_2614-1
RHSA-2019:2197
RHSA-2019_2197
RHSA-2020:1471
SUSE-SU-2019:1486-1
SUSE-SU-2019_1486-1
SUSE-SU-2022:2614-1
SUSE-SU-2022:2614-2
USN-4012-1

Affected Products

Alt Linux
Centos
Red Hat
Suse
Ubuntu
Elfutils