Search CVE reports


Toggle filters

21 – 30 of 33 results


CVE-2018-16062

Low priority
Fixed

dwarf_getaranges in dwarf_getaranges.c in libdw in elfutils before 2018-08-18 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file.

1 affected package

elfutils

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
elfutils Not affected Not affected Fixed Fixed
Show less packages

CVE-2018-8769

Medium priority
Not affected

elfutils 0.170 has a buffer over-read in the ebl_dynamic_tag_name function of libebl/ebldynamictagname.c because SYMTAB_SHNDX is unsupported.

1 affected package

elfutils

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
elfutils Not affected
Show less packages

CVE-2017-7613

Medium priority

Some fixes available 10 of 13

elflint.c in elfutils 0.168 does not validate the number of sections and the number of segments, which allows remote attackers to cause a denial of service (memory consumption) via a crafted ELF file.

1 affected package

elfutils

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
elfutils Fixed Fixed Fixed
Show less packages

CVE-2017-7612

Medium priority

Some fixes available 10 of 13

The check_sysv_hash function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file.

1 affected package

elfutils

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
elfutils Fixed Fixed Fixed
Show less packages

CVE-2017-7611

Medium priority

Some fixes available 10 of 13

The check_symtab_shndx function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file.

1 affected package

elfutils

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
elfutils Fixed Fixed Fixed
Show less packages

CVE-2017-7610

Medium priority

Some fixes available 10 of 13

The check_group function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file.

1 affected package

elfutils

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
elfutils Fixed Fixed Fixed
Show less packages

CVE-2017-7609

Medium priority

Some fixes available 3 of 6

elf_compress.c in elfutils 0.168 does not validate the zlib compression factor, which allows remote attackers to cause a denial of service (memory consumption) via a crafted ELF file.

1 affected package

elfutils

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
elfutils Fixed Fixed
Show less packages

CVE-2017-7608

Medium priority

Some fixes available 10 of 13

The ebl_object_note_type_name function in eblobjnotetypename.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file.

1 affected package

elfutils

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
elfutils Fixed Fixed Fixed
Show less packages

CVE-2017-7607

Medium priority

Some fixes available 10 of 13

The handle_gnu_hash function in readelf.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file.

1 affected package

elfutils

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
elfutils Fixed Fixed Fixed
Show less packages

CVE-2016-10255

Low priority

Some fixes available 10 of 13

The __libelf_set_rawdata_wrlock function in elf_getdata.c in elfutils before 0.168 allows remote attackers to cause a denial of service (crash) via a crafted (1) sh_off or (2) sh_size ELF header value, which triggers a memory...

1 affected package

elfutils

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
elfutils Fixed Fixed Fixed
Show less packages