CVE-2019-7146: Medium severity centos elfutils vulnerability
In elfutils 0.175, there is a buffer over-read in the eblobjectnote function in eblobjnote.c in libebl. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted elf file, as demonstrated by eu-readelf.
Other sources
In elfutils 0.175, there is a buffer over-read in the eblobjectnote function in eblobjnote.c in libebl. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted elf file.
References: https://sourceware.org/bugzilla/showbug.cgi?id=24075 https://sourceware.org/bugzilla/showbug.cgi?id=24081
Upstream Patch: https://sourceware.org/git/?p=elfutils.git;a=commit;h=012018907ca05eb0ab51d424a596ef38fc87cae1 https://sourceware.org/git/?p=elfutils.git;a=commit;h=cd7ded3df43f655af945c869976401a602e46fcd
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-7146?
CVE-2019-7146 is classified as a medium severity vulnerability due to its potential for denial-of-service attacks.
How do I fix CVE-2019-7146?
To fix CVE-2019-7146, upgrade to a patched version of elfutils beyond 0.175.
What type of vulnerability is CVE-2019-7146?
CVE-2019-7146 is a buffer over-read vulnerability that can lead to denial of service.
Which software versions are affected by CVE-2019-7146?
CVE-2019-7146 affects elfutils version 0.175.
Can CVE-2019-7146 be exploited remotely?
Yes, CVE-2019-7146 can be exploited remotely using a crafted ELF file.