Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Gentoo: GLSA-202303-15 Medium: libarchive Memory Corruption Vulnerability

gentoo
Calendar Grey December 13, 2016
Dist Gentoo Esm H88
A recent advisory on Elfutils highlights risks of a heap-based buffer overflow, potentially leading to remote code execution, especially on Gentoo. Admins should upgrade swiftly
A heap-based buffer overflow vulnerability in elfutils might allow remote attackers to execute arbitrary code.

Summary

An integer overflow, in the check_section function of dwarf_begin_elf.c, in the libdw library can lead to a heap-based buffer overflow.

Resolution

All elfutils users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=dev-libs/elfutils-0.159"

References

[ 1 ] CVE-2014-0172 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-0172

Availability

This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201612-32
style>.gentoo_availability{display:block;}

Concerns

Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org.

Severity
medium
Lowest
Low
Medium
High
Critical

Severity: Normal
Title: elfutils: Heap-based buffer overflow
Date: December 13, 2016
Bugs: #507246
ID: 201612-32

Synopsis

A heap-based buffer overflow vulnerability in elfutils might allow remote attackers to execute arbitrary code.

Background

Elfutils provides a library and utilities to access, modify and analyse ELF objects.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 dev-libs/elfutils < 0.159 >= 0.159

Impact

===== A remote attacker could entice a user to open a specially crafted file, possibly resulting in the execution of arbitrary code with the privileges of the process or a Denial of Service condition.

Workaround

There is no known workaround at this time.

Related News

Your message here