Alerts This Week
Warning Icon 1 684
Alerts This Week
Warning Icon 1 684

Debian 8: DLA-1689-1 Critical: elfutils Heap Overflow Issues

debian lts
Calendar Grey February 25, 2019
Dist Debian Esm H88
Package : elfutils Version : 0.159-4.2+deb8u1 CVE ID : CVE-2017-7608 CVE-2017-7610 CVE-2017-7611 CVE
Several issues in elfutils, a collection of utilities to handle ELF objects, have been found either by fuzzing or by using an AddressSanitizer

Summary

CVE-2019-7665
Due to a heap-buffer-overflow problem in function elf32_xlatetom()
a crafted ELF input can cause segmentation faults.

CVE-2019-7150
Add sanity check for partial core file dynamic data read.

CVE-2019-7149
Due to a heap-buffer-overflow problem in function read_srclines()
a crafted ELF input can cause segmentation faults.

CVE-2018-18521
By using a crafted ELF file, containing a zero sh_entsize, a
divide-by-zero vulnerability could allow remote attackers to
cause a denial of service (application crash).

CVE-2018-18520
By fuzzing an Invalid Address Deference problem in function elf_end
has been found.

CVE-2018-18310
By fuzzing an Invalid Address Read problem in eu-stack has been
found.

CVE-2018-16062
By using an AddressSanitizer a heap-buffer-overflow has been found.

CVE-2017-7613
By using fuzzing it was found that an allocation failure was not
handled properly.

CVE-2017-7612

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: elfutils
Version: 0.159-4.2+deb8u1
CVE ID: CVE-2017-7608 CVE-2017-7610 CVE-2017-7611 CVE-2017-7612

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here