REDHAT-BUG-1671432: Low severity elfutils vulnerability
In elfutils 0.175, there is a buffer over-read in the eblobjectnote function in eblobjnote.c in libebl. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted elf file.
References: https://sourceware.org/bugzilla/showbug.cgi?id=24075 https://sourceware.org/bugzilla/showbug.cgi?id=24081
Upstream Patch: https://sourceware.org/git/?p=elfutils.git;a=commit;h=012018907ca05eb0ab51d424a596ef38fc87cae1 https://sourceware.org/git/?p=elfutils.git;a=commit;h=cd7ded3df43f655af945c869976401a602e46fcd
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1671432?
REDHAT-BUG-1671432 has a severity rating that indicates it can lead to denial-of-service conditions.
How do I fix REDHAT-BUG-1671432?
To fix REDHAT-BUG-1671432, update the elfutils package to the latest patched version.
Can REDHAT-BUG-1671432 be exploited remotely?
Yes, REDHAT-BUG-1671432 can be exploited remotely through a crafted ELF file.
What software is affected by REDHAT-BUG-1671432?
The affected software for REDHAT-BUG-1671432 is the Elfutils package.
What kind of vulnerability is REDHAT-BUG-1671432?
REDHAT-BUG-1671432 is classified as a buffer over-read vulnerability.