ZeroHour

CVE-2019-7665

PoC ×2
CVSS 3.1
5.5 medium
EPSS
1%p69
Published
()
Modified
Description

In elfutils 0.175, a heap-based buffer over-read was discovered in the function elf32_xlatetom in elf32_xlatetom.c in libelf. A crafted ELF input can cause a segmentation fault leading to denial of service (program crash) because ebl_core_note does not reject malformed core file notes.

Vendors
elfutils projectdebiancanonicalopensuseredhat
Products
elfutils, debian linux, ubuntu linux, leap, enterprise linux, enterprise linux desktop, enterprise linux eus, enterprise linux server, enterprise linux server aus, enterprise linux server tus, enterprise linux workstation
Weakness
CWE-125
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.