CVE-2018-18310: Buffer Overflow
A flaw was found in elfutils through v0.174. An invalid memory address dereference was discovered in dwflsegmentreportmodule.c in libdwfl. The vulnerability allows attackers to cause a denial of service (application crash) with a crafted ELF file, as demonstrated by considernotes.
References: https://sourceware.org/bugzilla/showbug.cgi?id=23752 https://sourceware.org/ml/elfutils-devel/2018-q4/msg00022.html
Other sources
An invalid memory address dereference was discovered in dwflsegmentreportmodule.c in libdwfl in elfutils through v0.174. The vulnerability allows attackers to cause a denial of service (application crash) with a crafted ELF file, as demonstrated by considernotes.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-18310?
CVE-2018-18310 has been classified as a denial of service vulnerability due to an invalid memory address dereference.
How do I fix CVE-2018-18310?
To fix CVE-2018-18310, upgrade your elfutils package to version 0.183-1 or later.
Which versions of elfutils are affected by CVE-2018-18310?
CVE-2018-18310 affects elfutils versions up to and including 0.174.
Can CVE-2018-18310 lead to system crashes?
Yes, CVE-2018-18310 can cause application crashes if exploited with a crafted ELF file.
Which Linux distributions are impacted by CVE-2018-18310?
CVE-2018-18310 impacts several distributions including Debian, Red Hat, and Ubuntu for specific versions.