PT-2019-6429 · Red Hat+3 · Elfutils+3

Leftcopy.Chx

·

Published

2019-10-06

·

Updated

2023-09-23

·

CVE-2020-21047

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions elfutils version 0.177
Description The issue is related to a denial-of-service vulnerability in the libcpu component of elfutils, caused by application crashes due to out-of-bounds write, off-by-one error, and reachable assertion. Attackers can exploit this by crafting certain ELF files that bypass missing bound checks.
Recommendations For elfutils version 0.177, consider updating to a newer version that addresses the out-of-bounds write, off-by-one error, and reachable assertion issues to prevent application crashes and potential denial-of-service attacks. As a temporary workaround, restrict the use of specially crafted ELF files that could exploit the vulnerability.

Fix

DoS

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2024-06964
CVE-2020-21047
DLA-3579-1
USN-6322-1

Affected Products

Astra Linux
Linuxmint
Ubuntu
Elfutils