CVE-2021-33294: Medium severity centos elfutils vulnerability
Published Jul 18, 2023
·Updated
In elfutils 0.183, an infinite loop was found in the function handlesymtab in readelf.c .Which allows attackers to cause a denial of service (infinite loop) via crafted file.
Affected Software
2 affected componentsFixes available
debian/elfutils<=0.183-1
0.188-2.10.192-4
Elfutils Project Elfutils=0.183
Remediation
Event History
Jul 18, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
02:15 PM
Description
Data Sourced
via NVD·02:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·11:56 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·02:17 AM
RemedyDescriptionSeverityAffected Software
Dec 7, 2024
Data Sourced
via Debian·04:31 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-33294?
CVE-2021-33294 has been classified as a denial of service vulnerability due to an infinite loop in the elfutils library.
2
How do I fix CVE-2021-33294?
To fix CVE-2021-33294, upgrade elfutils to version 0.188-2.1 or later, or 0.192-4 or later.
3
What software is affected by CVE-2021-33294?
CVE-2021-33294 affects elfutils version 0.183 and older versions prior to 0.188-2.1 and 0.192-4.
4
What kind of attack can exploit CVE-2021-33294?
CVE-2021-33294 can be exploited to cause a denial of service through crafted ELF files leading to an infinite loop.
5
Is CVE-2021-33294 publicly known?
Yes, CVE-2021-33294 is publicly documented and reported in the elfutils project communications.