First published: Thu Mar 23 2017(Updated: )
Last updated 24 July 2024
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/elfutils | 0.183-1 0.188-2.1 0.191-2 | |
CentOS Elfutils | <=0.167 |
https://sourceware.org/git/?p=elfutils.git;a=commitdiff;h=191000fdedba3fafe4d5b8cddad3f3318b49c3fb
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-10254 is classified as a denial of service vulnerability that can lead to application crashes.
To fix CVE-2016-10254, upgrade to elfutils version 0.168 or later.
CVE-2016-10254 affects users of elfutils versions prior to 0.168.
The vulnerability in CVE-2016-10254 is caused by a memory allocation failure triggered by a crafted ELF file.
The affected software package for CVE-2016-10254 is elfutils, specifically versions prior to 0.168.