vulnerability

Amazon Linux AMI 2: CVE-2018-16402: Security patch for elfutils (ALAS-2019-1337)

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
Published
Sep 3, 2018
Added
Apr 27, 2020
Modified
Nov 27, 2024

Description

libelf/elf_end.c in elfutils 0.173 allows remote attackers to cause a denial of service (double free and application crash) or possibly have unspecified other impact because it tries to decompress twice.

Solution(s)

amazon-linux-ami-2-upgrade-elfutilsamazon-linux-ami-2-upgrade-elfutils-debuginfoamazon-linux-ami-2-upgrade-elfutils-default-yama-scopeamazon-linux-ami-2-upgrade-elfutils-develamazon-linux-ami-2-upgrade-elfutils-devel-staticamazon-linux-ami-2-upgrade-elfutils-libelfamazon-linux-ami-2-upgrade-elfutils-libelf-develamazon-linux-ami-2-upgrade-elfutils-libelf-devel-staticamazon-linux-ami-2-upgrade-elfutils-libs
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.