The libcpu component which is used by libasm of elfutils version 0.177 (git 47780c9e), suffers from denial-of-service vulnerability caused by application crashes due to out-of-bounds write (CWE-787), off-by-one error (CWE-193) and reachable assertion (CWE-617); to exploit the vulnerability, the attackers need to craft certain ELF files which bypass the missing bound checks.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade elfutilsUpgrade elfutils-devel-staticUpgrade elfutils-develUpgrade elfutils-libelfUpgrade elfutils-libelf-develUpgrade elfutils-libelf-devel-staticUpgrade elfutils-libsUpgrade elfutils-debuginfoUpgrade elfutils-default-yama-scope | Sep 21, 2023 | Aug 22, 2023 |
| Debian | — | Upgrade elfutils | Sep 25, 2023 | Aug 22, 2023 |
| Ubuntu | — | Upgrade libelf1 (Ubuntu Pro)Upgrade elfutilsUpgrade libelf1Upgrade libasm1 (Ubuntu Pro)Upgrade libdw1Upgrade elfutils (Ubuntu Pro)Upgrade libdw1 (Ubuntu Pro)Upgrade libasm1 | Aug 31, 2023 | Aug 22, 2023 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Aug 22, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub