4.3
CVSSv2

CVE-2019-7665

Published: 09/02/2019 Updated: 30/11/2021
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

In elfutils 0.175, a heap-based buffer over-read exists in the function elf32_xlatetom in elf32_xlatetom.c in libelf. A crafted ELF input can cause a segmentation fault leading to denial of service (program crash) because ebl_core_note does not reject malformed core file notes.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

elfutils project elfutils 0.175

debian debian linux 8.0

debian debian linux 9.0

canonical ubuntu linux 16.04

canonical ubuntu linux 18.04

canonical ubuntu linux 18.10

opensuse leap 15.0

opensuse leap 15.1

redhat enterprise linux 8.0

redhat enterprise linux desktop 7.0

redhat enterprise linux eus 8.1

redhat enterprise linux eus 8.2

redhat enterprise linux eus 8.4

redhat enterprise linux server 7.0

redhat enterprise linux server aus 8.2

redhat enterprise linux server aus 8.4

redhat enterprise linux server tus 8.2

redhat enterprise linux server tus 8.4

redhat enterprise linux workstation 7.0

Vendor Advisories

Several security issues were fixed in elfutils ...
Synopsis Low: elfutils security, bug fix, and enhancement update Type/Severity Security Advisory: Low Topic An update for elfutils is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Low A Common Vulnerability Scoring System (CVSS) b ...
Synopsis Low: elfutils security, bug fix, and enhancement update Type/Severity Security Advisory: Low Topic An update for elfutils is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Low A Common Vulnerability Scoring System (CVSS) b ...
Synopsis Moderate: OpenShift Container Platform 461 image security update Type/Severity Security Advisory: Moderate Topic An update is now available for Red Hat OpenShift Container Platform 46Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability S ...
Debian Bug report logs - #920909 elfutils: CVE-2019-7150 Package: src:elfutils; Maintainer for src:elfutils is Kurt Roeckx <kurt@roeckxbe>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 30 Jan 2019 14:33:02 UTC Severity: normal Tags: fixed-upstream, patch, security, upstream Found in version elfu ...
Debian Bug report logs - #920910 elfutils: CVE-2019-7149 Package: src:elfutils; Maintainer for src:elfutils is Kurt Roeckx <kurt@roeckxbe>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 30 Jan 2019 14:33:04 UTC Severity: normal Tags: fixed-upstream, security, upstream Found in version elfutils/0 ...
Debian Bug report logs - #920911 elfutils: CVE-2019-7146 Package: src:elfutils; Maintainer for src:elfutils is Kurt Roeckx <kurt@roeckxbe>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 30 Jan 2019 14:33:07 UTC Severity: normal Tags: fixed-upstream, security, upstream Found in version elfutils/0 ...
Debian Bug report logs - #921881 elfutils: CVE-2019-7664 Package: src:elfutils; Maintainer for src:elfutils is Kurt Roeckx <kurt@roeckxbe>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 9 Feb 2019 20:27:04 UTC Severity: normal Tags: fixed-upstream, security, upstream Found in version elfutils/0 ...
Debian Bug report logs - #921880 elfutils: CVE-2019-7665 Package: src:elfutils; Maintainer for src:elfutils is Kurt Roeckx <kurt@roeckxbe>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 9 Feb 2019 20:27:01 UTC Severity: normal Tags: fixed-upstream, security, upstream Found in version elfutils/0 ...
An out-of-bounds read was discovered in elfutils in the way it reads DWARF address ranges information Function dwarf_getaranges() in dwarf_getarangesc does not properly check whether it reads beyond the limits of the ELF section An attacker could use this flaw to cause a denial of service via a crafted file(CVE-2018-16062) libelf/elf_endc in e ...
In elfutils 0175, a heap-based buffer over-read was discovered in the function elf32_xlatetom in elf32_xlatetomc in libelf A crafted ELF input can cause a segmentation fault leading to denial of service (program crash) because ebl_core_note does not reject malformed core file notes ...