PT-2019-6429 · Red Hat+3 · Elfutils+3
Leftcopy.Chx
·
Published
2019-10-06
·
Updated
2023-09-23
·
CVE-2020-21047
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
elfutils version 0.177
Description
The issue is related to a denial-of-service vulnerability in the libcpu component of elfutils, caused by application crashes due to out-of-bounds write, off-by-one error, and reachable assertion. Attackers can exploit this by crafting certain ELF files that bypass missing bound checks.
Recommendations
For elfutils version 0.177, consider updating to a newer version that addresses the out-of-bounds write, off-by-one error, and reachable assertion issues to prevent application crashes and potential denial-of-service attacks. As a temporary workaround, restrict the use of specially crafted ELF files that could exploit the vulnerability.
Fix
DoS
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Linuxmint
Ubuntu
Elfutils