The package libelf before version 0.176-1 is vulnerable to denial of service. . Arch Linux Security Advisory ASA-201903-9 ======================================== Severity: Medium Date : 2019-03-18 CVE-ID : CVE-2019-7148 CVE-2019-7149 CVE-2019-7150 CVE-2019-7664 CVE-2019-7665 Package : libelf Type : denial of service Remote : Yes Link : https://security.archlinux.org/AVG-863 Summary ====== The package libelf before version 0.176-1 is vulnerable to denial of service. Resolution ========= Upgrade to 0.176-1. # pacman -Syu "libelf> =0.176-1" The problems have been fixed upstream in version 0.176. Workaround ========= None. Description ========== - CVE-2019-7148 (denial of service) An attempted excessive memory allocation was discovered in the function read_long_names in elf_begin.c in libelf in elfutils
Get the latest Linux and open source security news straight to your inbox.