CVE-2019-7664: Medium severity centos elfutils vulnerability
In elfutils 0.175, a negative-sized memcpy is attempted in elfcvtnote in libelf/notexlate.h because of an incorrect overflow check. Crafted elf input causes a segmentation fault, leading to denial of service (program crash).
Reference: https://sourceware.org/bugzilla/showbug.cgi?id=24084
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-7664?
CVE-2019-7664 has a severity rating that typically qualifies it as a denial of service vulnerability.
How do I fix CVE-2019-7664?
To fix CVE-2019-7664, update to a patched version of elfutils beyond 0.175 that addresses this overflow vulnerability.
What systems are affected by CVE-2019-7664?
CVE-2019-7664 affects systems running elfutils version 0.175 and various Red Hat Enterprise Linux versions including 7.0 and 8.0 through 8.6.
What type of vulnerability is CVE-2019-7664?
CVE-2019-7664 is classified as a memory corruption vulnerability that can lead to a program crash.
Can exploitation of CVE-2019-7664 lead to data exposure?
Exploitation of CVE-2019-7664 primarily results in denial of service and does not directly lead to data exposure.