Integer overflow in the check_section function in dwarf_begin_elf.c in the libdw library, as used in elfutils 0.153 and possibly through 0.158 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a malformed compressed debug section in an ELF file, which triggers a heap-based buffer overflow.
CVSS Details
- CVSS 3.1 Base Score: 8.4
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade elfutils | Jul 30, 2024 | Apr 11, 2014 |
| Gentoo Linux | — | Upgrade dev-libs/elfutils. | Oct 30, 2017 | Apr 11, 2014 |
| Suse | — | Upgrade libebl1-32bitUpgrade libdw1-32bitUpgrade libebl1Upgrade libelf1-32bitUpgrade libebl-develUpgrade libebl-plugins-32bitUpgrade libdw-develUpgrade libelf-develUpgrade elfutilsUpgrade libasm-develUpgrade libasm1-32bitUpgrade libdw1Upgrade elfutils-langUpgrade libebl-pluginsUpgrade libelf1Upgrade libasm1 | Dec 18, 2015 | Apr 11, 2014 |
| Ubuntu | — | Upgrade libdw1 | Nov 8, 2024 | Apr 11, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub