4.3
CVSSv2

CVE-2019-7150

Published: 29/01/2019 Updated: 30/11/2021
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

An issue exists in elfutils 0.175. A segmentation fault can occur in the function elf64_xlatetom in libelf/elf32_xlatetom.c, due to dwfl_segment_report_module not checking whether the dyn data read from a core file is truncated. A crafted input can cause a program crash, leading to denial-of-service, as demonstrated by eu-stack.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

elfutils project elfutils 0.175

debian debian linux 8.0

debian debian linux 9.0

canonical ubuntu linux 16.04

canonical ubuntu linux 18.04

canonical ubuntu linux 18.10

opensuse leap 15.0

opensuse leap 15.1

redhat enterprise linux 8.0

redhat enterprise linux desktop 7.0

redhat enterprise linux eus 8.1

redhat enterprise linux eus 8.2

redhat enterprise linux eus 8.4

redhat enterprise linux server 7.0

redhat enterprise linux server aus 8.2

redhat enterprise linux server aus 8.4

redhat enterprise linux server tus 8.2

redhat enterprise linux server tus 8.4

redhat enterprise linux workstation 7.0

Vendor Advisories

Several security issues were fixed in elfutils ...
Synopsis Low: elfutils security, bug fix, and enhancement update Type/Severity Security Advisory: Low Topic An update for elfutils is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Low A Common Vulnerability Scoring System (CVSS) b ...
Synopsis Low: elfutils security, bug fix, and enhancement update Type/Severity Security Advisory: Low Topic An update for elfutils is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Low A Common Vulnerability Scoring System (CVSS) b ...
Synopsis Moderate: OpenShift Container Platform 461 image security update Type/Severity Security Advisory: Moderate Topic An update is now available for Red Hat OpenShift Container Platform 46Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability S ...
Debian Bug report logs - #920909 elfutils: CVE-2019-7150 Package: src:elfutils; Maintainer for src:elfutils is Kurt Roeckx <kurt@roeckxbe>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 30 Jan 2019 14:33:02 UTC Severity: normal Tags: fixed-upstream, patch, security, upstream Found in version elfu ...
Debian Bug report logs - #920910 elfutils: CVE-2019-7149 Package: src:elfutils; Maintainer for src:elfutils is Kurt Roeckx <kurt@roeckxbe>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 30 Jan 2019 14:33:04 UTC Severity: normal Tags: fixed-upstream, security, upstream Found in version elfutils/0 ...
Debian Bug report logs - #920911 elfutils: CVE-2019-7146 Package: src:elfutils; Maintainer for src:elfutils is Kurt Roeckx <kurt@roeckxbe>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 30 Jan 2019 14:33:07 UTC Severity: normal Tags: fixed-upstream, security, upstream Found in version elfutils/0 ...
Debian Bug report logs - #921881 elfutils: CVE-2019-7664 Package: src:elfutils; Maintainer for src:elfutils is Kurt Roeckx <kurt@roeckxbe>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 9 Feb 2019 20:27:04 UTC Severity: normal Tags: fixed-upstream, security, upstream Found in version elfutils/0 ...
Debian Bug report logs - #921880 elfutils: CVE-2019-7665 Package: src:elfutils; Maintainer for src:elfutils is Kurt Roeckx <kurt@roeckxbe>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 9 Feb 2019 20:27:01 UTC Severity: normal Tags: fixed-upstream, security, upstream Found in version elfutils/0 ...
An out-of-bounds read was discovered in elfutils in the way it reads DWARF address ranges information Function dwarf_getaranges() in dwarf_getarangesc does not properly check whether it reads beyond the limits of the ELF section An attacker could use this flaw to cause a denial of service via a crafted file(CVE-2018-16062) libelf/elf_endc in e ...
An issue was discovered in elfutils 0175 A segmentation fault can occur in the function elf64_xlatetom in libelf/elf32_xlatetomc, due to dwfl_segment_report_module not checking whether the dyn data read from a core file is truncated A crafted input can cause a program crash, leading to denial-of-service ...