CVE-2019-7149: Medium severity Elfutils Project Elfutils vulnerability
Published Jan 29, 2019
·Updated
A heap-based buffer over-read was discovered in the function readsrclines in dwarfgetsrclines.c in libdw in elfutils 0.175. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by eu-nm.
Affected Software
3 affected componentsFixes available
Elfutils Project Elfutils=0.175
Debian Debian Linux=8.0
debian/elfutils
0.183-10.188-2.10.192-40.194-1
Remediation
Event History
Jan 29, 2019
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Jan 31, 2019
Data Sourced
via Red Hat·03:34 PM
DescriptionSeverityAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·11:31 PM
Description
Feb 20, 2026
Data Sourced
via Ubuntu·05:30 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·05:31 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-7149?
CVE-2019-7149 has a medium severity rating due to its potential to cause denial-of-service through segmentation faults.
2
How do I fix CVE-2019-7149?
To fix CVE-2019-7149, upgrade libdw in elfutils to versions 0.183-1, 0.188-2.1, or 0.192-4 or later.
3
What type of vulnerability is CVE-2019-7149?
CVE-2019-7149 is a heap-based buffer over-read vulnerability.
4
What software is affected by CVE-2019-7149?
CVE-2019-7149 affects elfutils version 0.175 and specific Debian Linux distributions.
5
What are the potential impacts of CVE-2019-7149?
The potential impacts of CVE-2019-7149 include application crashes and denial-of-service conditions.