PT-2019-6429 · Red Hat+3 · Elfutils+3

·

CVE-2020-21047

·

Published

2019-10-06

·

Updated

2023-09-23

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions elfutils version 0.177
Description The issue is related to a denial-of-service vulnerability in the libcpu component of elfutils, caused by application crashes due to out-of-bounds write, off-by-one error, and reachable assertion. Attackers can exploit this by crafting certain ELF files that bypass missing bound checks.
Recommendations For elfutils version 0.177, consider updating to a newer version that addresses the out-of-bounds write, off-by-one error, and reachable assertion issues to prevent application crashes and potential denial-of-service attacks. As a temporary workaround, restrict the use of specially crafted ELF files that could exploit the vulnerability.

Fix

DoS

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-06964
CVE-2020-21047
DLA-3579-1
USN-6322-1

Affected Products

Astra Linux
Linuxmint
Ubuntu
Elfutils