The libcpu component which is used by libasm of elfutils version 0.177 (git 47780c9e), suffers from denial-of-service vulnerability caused by application crashes due to out-of-bounds write (CWE-787), off-by-one error (CWE-193) and reachable assertion (CWE-617); to exploit the vulnerability, the attackers need to craft certain ELF files which bypass the missing bound checks.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade elfutils-develUpgrade elfutils-devel-staticUpgrade elfutilsUpgrade elfutils-default-yama-scopeUpgrade elfutils-debuginfoUpgrade elfutils-libelfUpgrade elfutils-libelf-devel-staticUpgrade elfutils-libelf-develUpgrade elfutils-libs | Sep 21, 2023 | Aug 22, 2023 |
| Debian | — | Upgrade elfutils | Sep 25, 2023 | Aug 22, 2023 |
| Ubuntu | — | Upgrade elfutils (Ubuntu Pro)Upgrade libdw1 (Ubuntu Pro)Upgrade libasm1Upgrade libdw1Upgrade libasm1 (Ubuntu Pro)Upgrade libelf1Upgrade elfutilsUpgrade libelf1 (Ubuntu Pro) | Aug 31, 2023 | Aug 22, 2023 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Aug 22, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub