CVE-2019-7150: Medium severity Elfutils Project Elfutils vulnerability
An issue was discovered in elfutils 0.175. A segmentation fault can occur in the function elf64xlatetom in libelf/elf32xlatetom.c, due to dwflsegmentreportmodule not checking whether the dyn data read from a core file is truncated. A crafted input can cause a program crash, leading to denial-of-service, as demonstrated by eu-stack.
Affected Software
Remediation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2019-7150?
CVE-2019-7150 is classified as a moderate severity vulnerability due to potential denial of service from a segmentation fault.
How do I fix CVE-2019-7150?
To remediate CVE-2019-7150, upgrade to elfutils version 0.176-2.el7 or 0.176-5.el8 for Red Hat or the appropriate updated version for Debian and Ubuntu.
Which software versions are affected by CVE-2019-7150?
CVE-2019-7150 affects elfutils version 0.175 and could impact various distributions such as Red Hat, Debian, and Ubuntu.
What kind of issue does CVE-2019-7150 cause?
CVE-2019-7150 can cause a segmentation fault leading to a program crash and potential denial of service.
Is there a risk of exploitation for CVE-2019-7150?
While CVE-2019-7150 can lead to crashes, exploitation risk is contingent upon the context and provided payload used.