CVE-2018-16062: Medium severity Elfutils Project Elfutils vulnerability
An out-of-bounds read was discovered in elfutils in the way it reads DWARF address ranges information. Function dwarfgetaranges() in dwarfgetaranges.c does not properly check whether it reads beyond the limits of the ELF section. An attacker could use this flaw to cause a denial of service via a crafted file.
Other sources
dwarfgetaranges in dwarfgetaranges.c in libdw in elfutils before 2018-08-18 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file.
Elfutils is vulnerable to a heap-based buffer over-read in the libdw/dwarfgetaranges.c:dwarfgetaranges() function. An attacker could exploit this to cause a crash in the eu-addr2line command via a crafted file.
Upstream Bug:
https://sourceware.org/bugzilla/showbug.cgi?id=23541
Upstream Patch:
https://sourceware.org/git/?p=elfutils.git;a=commit;h=29e31978ba51c1051743a503ee325b5ebc03d7e9
— Red Hat
Affected Software
Remediation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2018-16062?
The severity of CVE-2018-16062 is rated as medium, indicating a moderate potential impact.
How do I fix CVE-2018-16062?
To mitigate CVE-2018-16062, update the affected elfutils package to at least version 0:0.176-2.el7 for Red Hat or the recommended versions for Debian and Ubuntu.
What systems are affected by CVE-2018-16062?
CVE-2018-16062 affects multiple Linux distributions including Red Hat Enterprise Linux, Debian, and Ubuntu systems running specific versions of the elfutils package.
What type of vulnerability is CVE-2018-16062?
CVE-2018-16062 is classified as an out-of-bounds read vulnerability leading to potential denial of service.
Is there a known exploit for CVE-2018-16062?
As of now, there are no publicly available exploits specifically targeting CVE-2018-16062.