USN-3670-1: elfutils vulnerabilities
5 June 2018
elfutils could be made to crash or consume resources if it opened a specially crafted file.
Releases
Packages
- elfutils - collection of utilities to handle ELF objects
Details
Agostino Sarubbo discovered that elfutils incorrectly handled certain
malformed ELF files. If a user or automated system were tricked into
processing a specially crafted ELF file, elfutils could be made to crash or
consume resources, resulting in a denial of service.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 16.04
-
elfutils
-
0.165-3ubuntu1.1
-
libasm1
-
0.165-3ubuntu1.1
-
libdw1
-
0.165-3ubuntu1.1
-
libelf1
-
0.165-3ubuntu1.1
Ubuntu 14.04
-
elfutils
-
0.158-0ubuntu5.3
-
libasm1
-
0.158-0ubuntu5.3
-
libdw1
-
0.158-0ubuntu5.3
-
libelf1
-
0.158-0ubuntu5.3
In general, a standard system update will make all the necessary changes.