CVE-2017-7607: Medium severity Elfutils Project Elfutils vulnerability
Last updated 25 August 2025
Other sources
The handlegnuhash function in readelf.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/elfutilsto a version that resolves this vulnerability.Fixed in 0.183-1Fixed in 0.188-2.1Fixed in 0.192-4Fixed in 0.195-1
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7607?
CVE-2017-7607 has been classified as a denial of service vulnerability due to a heap-based buffer over-read that can cause application crashes.
How do I fix CVE-2017-7607?
To fix CVE-2017-7607, update the elfutils package to version 0.183-1 or later in Debian systems.
What software is affected by CVE-2017-7607?
CVE-2017-7607 affects elfutils version 0.168 specifically, alongside its packages in Debian.
Can CVE-2017-7607 be exploited remotely?
Yes, CVE-2017-7607 can be exploited by remote attackers through specially crafted ELF files.
What are the consequences of exploiting CVE-2017-7607?
Exploiting CVE-2017-7607 can lead to application crashes and denial of service, impacting system availability.