REDHAT-BUG-1623752: Low severity elfutils vulnerability
Elfutils is vulnerable to a heap-based buffer over-read in the libdw/dwarfgetaranges.c:dwarfgetaranges() function. An attacker could exploit this to cause a crash in the eu-addr2line command via a crafted file.
Upstream Bug:
https://sourceware.org/bugzilla/showbug.cgi?id=23541
Upstream Patch:
https://sourceware.org/git/?p=elfutils.git;a=commit;h=29e31978ba51c1051743a503ee325b5ebc03d7e9
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1623752?
The severity of REDHAT-BUG-1623752 is classified as a moderate vulnerability.
How do I fix REDHAT-BUG-1623752?
To fix REDHAT-BUG-1623752, update to the latest version of Elfutils that addresses this vulnerability.
What is the impact of REDHAT-BUG-1623752?
The impact of REDHAT-BUG-1623752 includes potential crashes of the eu-addr2line command when processing specially crafted files.
Who is affected by REDHAT-BUG-1623752?
Users of Elfutils, specifically those using the eu-addr2line command, are affected by REDHAT-BUG-1623752.
Can REDHAT-BUG-1623752 be exploited remotely?
Yes, REDHAT-BUG-1623752 can potentially be exploited remotely if an attacker provides a crafted file to the affected system.