CVE-2014-0172: Buffer Overflow
Integer overflow in the checksection function in dwarfbeginelf.c in the libdw library, as used in elfutils 0.153 and possibly through 0.158 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a malformed compressed debug section in an ELF file, which triggers a heap-based buffer overflow.
Other sources
The libdw library provides support for accessing DWARF debugging information inside ELF files. An integer overflow flaw in checksection(), leading to a heap-based buffer overflow, was found in the libdw library. A malicious ELF file could cause an application using libdw (such as eu-readelf) to crash or, potentially, execute arbitrary code with the privileges of the user running the application.
Acknowledgements:
This issue was discovered by Florian Weimer of the Red Hat Product Security Team.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/elfutilsto a version that resolves this vulnerability.Fixed in 0.160
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0172?
CVE-2014-0172 is a medium severity vulnerability that can lead to application crashes or potentially allow arbitrary code execution.
How do I fix CVE-2014-0172?
To fix CVE-2014-0172, upgrade the elfutils package to version 0.160 or later.
Which versions of elfutils are affected by CVE-2014-0172?
CVE-2014-0172 affects elfutils versions 0.153 through 0.158.
What type of attack does CVE-2014-0172 enable?
CVE-2014-0172 enables remote attackers to perform denial of service attacks or potentially execute arbitrary code.
Who is affected by CVE-2014-0172?
Users and systems utilizing affected versions of elfutils are at risk of CVE-2014-0172.