PT-2019-1676 · Red Hat+5 · Elfutils+6

Wcventure

·

Published

2018-10-10

·

Updated

2023-08-30

·

CVE-2019-7150

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions elfutils version 0.175
Description An issue in the elf64 xlatetom function in libelf/elf32 xlatetom.c can cause a segmentation fault due to dwfl segment report module not checking whether the dyn data read from a core file is truncated. A crafted input can lead to a program crash, resulting in denial-of-service. This issue is demonstrated by eu-stack.
Recommendations For elfutils version 0.175, consider disabling the elf64 xlatetom function in libelf/elf32 xlatetom.c as a temporary workaround to minimize the risk of exploitation. However, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Out of bounds Read

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1249
BDU:2019-01238
CESA-2019_2197
CESA-2019_3575
CVE-2019-7150
DLA-1689-1
DLA-2802-1
MGASA-2019-0222
OPENSUSE-SU-2019:1590-1
OPENSUSE-SU-2019_1590-1
OPENSUSE-SU-2022_2614-1
RHSA-2019:2197
RHSA-2019:3575
RHSA-2019_2197
RHSA-2019_3575
SUSE-SU-2019:1486-1
SUSE-SU-2019:1733-1
SUSE-SU-2019_1486-1
SUSE-SU-2022:2614-1
SUSE-SU-2022:2614-2
USN-4012-1
USN-6322-1

Affected Products

Alt Linux
Centos
Linuxmint
Red Hat
Suse
Ubuntu
Elfutils