CVE-2018-16403: Medium severity Elfutils Project Elfutils vulnerability
Elfutils through version 0.173 is vulnerable to a heap-based buffer over-read due to incorrect checks for the end of attribute lists in the libdw/dwarfgetabbrev.c:libdwgetabbrev() and libdw/dwarfhasattr.c:dwarfhasattr() functions. An attacker could exploit this to cause a crash via a crafted ELF.
Upstream Bug:
https://sourceware.org/bugzilla/showbug.cgi?id=23529
Upstream Patch:
https://sourceware.org/git/?p=elfutils.git;a=patch;h=6983e59b727458a6c64d9659c85f08218bc4fcda
Other sources
libdw in elfutils 0.173 checks the end of the attributes list incorrectly in dwarfgetabbrev in dwarfgetabbrev.c and dwarfhasattr in dwarfhasattr.c, leading to a heap-based buffer over-read and an application crash.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-16403?
CVE-2018-16403 is rated as a medium severity vulnerability due to its potential to cause application crashes.
How do I fix CVE-2018-16403?
To fix CVE-2018-16403, upgrade to a patched version of elfutils, specifically version 0.183-1 or later.
What types of attacks can exploit CVE-2018-16403?
CVE-2018-16403 can be exploited by attackers through crafted ELF files to trigger heap-based buffer over-reads.
Which versions of elfutils are affected by CVE-2018-16403?
CVE-2018-16403 affects elfutils versions up to and including 0.173.
Where can I find more information about CVE-2018-16403?
More detailed information about CVE-2018-16403 can typically be found in security bulletins relevant to the affected distributions.