CVE Vulnerabilities

CVE-2014-0172

Published: Apr 11, 2014 | Modified: Jul 01, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
4.4 MODERATE
AV:L/AC:M/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM

Integer overflow in the check_section function in dwarf_begin_elf.c in the libdw library, as used in elfutils 0.153 and possibly through 0.158 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a malformed compressed debug section in an ELF file, which triggers a heap-based buffer overflow.

Affected Software

Name Vendor Start Version End Version
Elfutils Elfutils_project 0.153 (including) 0.153 (including)
Elfutils Elfutils_project 0.154 (including) 0.154 (including)
Elfutils Elfutils_project 0.155 (including) 0.155 (including)
Elfutils Elfutils_project 0.156 (including) 0.156 (including)
Elfutils Elfutils_project 0.157 (including) 0.157 (including)
Elfutils Elfutils_project 0.158 (including) 0.158 (including)
Red Hat Enterprise Linux 7 RedHat elfutils-0:0.160-1.el7 *
Elfutils Ubuntu devel *
Elfutils Ubuntu quantal *
Elfutils Ubuntu saucy *
Elfutils Ubuntu trusty *

References