CVE-2017-7609: Input Validation
elfcompress.c in elfutils 0.168 does not validate the zlib compression factor, which allows remote attackers to cause a denial of service (memory consumption) via a crafted ELF file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/elfutilsto a version that resolves this vulnerability.Fixed in 0.183-1Fixed in 0.188-2.1Fixed in 0.192-4Fixed in 0.195-1
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7609?
CVE-2017-7609 is classified as a denial of service vulnerability due to memory consumption issues caused by a crafted ELF file.
How do I fix CVE-2017-7609?
To fix CVE-2017-7609, upgrade elfutils to version 0.183-1 or later.
Which versions of elfutils are affected by CVE-2017-7609?
CVE-2017-7609 affects elfutils version 0.168 but not the versions 0.183-1, 0.188-2.1, or 0.191-2.
What type of attacks can exploit CVE-2017-7609?
Attackers can exploit CVE-2017-7609 to create a crafted ELF file that leads to denial of service through excessive memory consumption.
Is CVE-2017-7609 specific to any operating system?
CVE-2017-7609 is particularly relevant for systems using the elfutils package, including certain distributions of Debian.