CVE-2019-7665: Medium severity Elfutils Project Elfutils vulnerability
In elfutils 0.175, a heap-based buffer over-read was discovered in the function elf32xlatetom in elf32xlatetom.c in libelf. A crafted ELF input can cause a segmentation fault leading to denial of service (program crash) because eblcorenote does not reject malformed core file notes.
References: https://sourceware.org/bugzilla/showbug.cgi?id=24089 https://sourceware.org/ml/elfutils-devel/2019-q1/msg00049.html
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-7665?
The severity of CVE-2019-7665 is classified as high due to the potential for denial of service.
How do I fix CVE-2019-7665?
To fix CVE-2019-7665, you should upgrade to elfutils version 0.183-1 or later.
Which versions are affected by CVE-2019-7665?
CVE-2019-7665 affects elfutils version 0.175 and earlier versions.
What systems are vulnerable to CVE-2019-7665?
Vulnerable systems include Debian 8.0, Debian 9.0, Ubuntu 16.04, Ubuntu 18.04, and various versions of Red Hat Enterprise Linux.
What type of vulnerability is CVE-2019-7665?
CVE-2019-7665 is classified as a heap-based buffer over-read vulnerability.