REDHAT-BUG-1625055: Low severity elfutils vulnerability
Elfutils through version 0.173 is vulnerable to a heap-based buffer over-read due to incorrect checks for the end of attribute lists in the libdw/dwarfgetabbrev.c:libdwgetabbrev() and libdw/dwarfhasattr.c:dwarfhasattr() functions. An attacker could exploit this to cause a crash via a crafted ELF.
Upstream Bug:
https://sourceware.org/bugzilla/showbug.cgi?id=23529
Upstream Patch:
https://sourceware.org/git/?p=elfutils.git;a=patch;h=6983e59b727458a6c64d9659c85f08218bc4fcda
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1625055?
The severity of REDHAT-BUG-1625055 is classified as a moderate vulnerability due to potential crash exploitation.
How do I fix REDHAT-BUG-1625055?
To fix REDHAT-BUG-1625055, upgrade Elfutils to a version later than 0.173 that includes the necessary patches.
Which versions of Elfutils are affected by REDHAT-BUG-1625055?
Elfutils versions up to and including 0.173 are affected by REDHAT-BUG-1625055.
What kind of exploit is possible with REDHAT-BUG-1625055?
An attacker could exploit REDHAT-BUG-1625055 to cause a crash via a crafted ELF file.
Are there any workarounds for REDHAT-BUG-1625055?
There are no official workarounds for REDHAT-BUG-1625055; updating to a patched version is recommended.