CVE-2017-7613: Input Validation
elflint.c in elfutils 0.168 does not validate the number of sections and the number of segments, which allows remote attackers to cause a denial of service (memory consumption) via a crafted ELF file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/elfutilsto a version that resolves this vulnerability.Fixed in 0.183-1Fixed in 0.188-2.1Fixed in 0.192-4Fixed in 0.195-1 - Upgrade
Upgrade
elfutils/elflintto a version that resolves this vulnerability.Fixed in 0.168 - Compensating control
Mitigate denial-of-service risk by restricting remote access to any service or workflow that processes untrusted ELF files (e.g., limit who can submit/upload ELF inputs).
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7613?
CVE-2017-7613 is classified as a denial of service vulnerability.
How do I fix CVE-2017-7613?
To fix CVE-2017-7613, you should upgrade to elfutils versions 0.183-1, 0.188-2.1, or 0.191-2.
What software is affected by CVE-2017-7613?
CVE-2017-7613 affects elfutils version 0.168 and it is present in various Linux distributions including Debian and Ubuntu.
What can exploit CVE-2017-7613?
A remote attacker can exploit CVE-2017-7613 by sending a crafted ELF file to trigger memory consumption.
When was CVE-2017-7613 last updated?
CVE-2017-7613 was last updated on 24 July 2024.