CVE-2016-10255
published 2017-03-23CVE-2016-10255: The __libelf_set_rawdata_wrlock function in elf_getdata.c in elfutils before 0.168 allows remote attackers to cause a denial of service (crash) via a crafted…
PriorityP419medium5.5CVSS 3.0
AVLACLPRNUIRSUCNINAH
EPSS
1.65%
73.8th percentile
The __libelf_set_rawdata_wrlock function in elf_getdata.c in elfutils before 0.168 allows remote attackers to cause a denial of service (crash) via a crafted (1) sh_off or (2) sh_size ELF header value, which triggers a memory allocation failure.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | elfutils | < elfutils 0.168-0.2 (bookworm) | elfutils 0.168-0.2 (bookworm) |
| elfutils_project | elfutils | <= 0.167 | — |
| elfutils_project | elfutils | >= 0 < 0.168-0.2 | 0.168-0.2 |
| elfutils_project | elfutils | >= 0 < 0.168-0.2 | 0.168-0.2 |
| elfutils_project | elfutils | >= 0 < 0.168-0.2 | 0.168-0.2 |
| elfutils_project | elfutils | >= 0 < 0.168-0.2 | 0.168-0.2 |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-j343-3qch-m53h: The __libelf_set_rawdata_wrlock function in elf_getdata
ghsa_unreviewed·2022-05-14
CVE-2016-10255 [MEDIUM] CWE-119 GHSA-j343-3qch-m53h: The __libelf_set_rawdata_wrlock function in elf_getdata
The __libelf_set_rawdata_wrlock function in elf_getdata.c in elfutils before 0.168 allows remote attackers to cause a denial of service (crash) via a crafted (1) sh_off or (2) sh_size ELF header value, which triggers a memory allocation failure.
OSV
CVE-2016-10255: The __libelf_set_rawdata_wrlock function in elf_getdata
osv·2017-03-23·CVSS 5.5
CVE-2016-10255 [MEDIUM] CVE-2016-10255: The __libelf_set_rawdata_wrlock function in elf_getdata
The __libelf_set_rawdata_wrlock function in elf_getdata.c in elfutils before 0.168 allows remote attackers to cause a denial of service (crash) via a crafted (1) sh_off or (2) sh_size ELF header value, which triggers a memory allocation failure.
Ubuntu
elfutils vulnerabilities
vendor_ubuntu·2018-06-05
CVE-2016-10254 elfutils vulnerabilities
Title: elfutils vulnerabilities
Summary: elfutils could be made to crash or consume resources if it opened a
specially crafted file.
Agostino Sarubbo discovered that elfutils incorrectly handled certain
malformed ELF files. If a user or automated system were tricked into
processing a specially crafted ELF file, elfutils could be made to crash or
consume resources, resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
elfutils: Memory allocation failure in __libelf_set_rawdata_wrlock (elf_getdata.c)
vendor_redhat·2016-11-09·CVSS 5.5
CVE-2016-10255 [MEDIUM] elfutils: Memory allocation failure in __libelf_set_rawdata_wrlock (elf_getdata.c)
elfutils: Memory allocation failure in __libelf_set_rawdata_wrlock (elf_getdata.c)
The __libelf_set_rawdata_wrlock function in elf_getdata.c in elfutils before 0.168 allows remote attackers to cause a denial of service (crash) via a crafted (1) sh_off or (2) sh_size ELF header value, which triggers a memory allocation failure.
Package: elfutils (Red Hat Enterprise Linux 5) - Will not fix
Package: elfutils (Red Hat Enterprise Linux 6) - Will not fix
Package: elfutils (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2016-10255: elfutils - The __libelf_set_rawdata_wrlock function in elf_getdata.c in elfutils before 0.1...
vendor_debian·2016·CVSS 5.5
CVE-2016-10255 [MEDIUM] CVE-2016-10255: elfutils - The __libelf_set_rawdata_wrlock function in elf_getdata.c in elfutils before 0.1...
The __libelf_set_rawdata_wrlock function in elf_getdata.c in elfutils before 0.168 allows remote attackers to cause a denial of service (crash) via a crafted (1) sh_off or (2) sh_size ELF header value, which triggers a memory allocation failure.
Scope: local
bookworm: resolved (fixed in 0.168-0.2)
bullseye: resolved (fixed in 0.168-0.2)
forky: resolved (fixed in 0.168-0.2)
sid: resolved (fixed in 0.168-0.2)
trixie: resolved (fixed in 0.168-0.2)
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2017/03/22/1https://blogs.gentoo.org/ago/2016/11/04/elfutils-memory-allocation-failure-in-__libelf_set_rawdata_wrlock-elf_getdata-c/https://bugzilla.redhat.com/show_bug.cgi?id=1387584https://lists.fedorahosted.org/archives/list/elfutils-devel%40lists.fedorahosted.org/thread/Q4LE47FPEVRZANMV6JE2NMHYO4H5MHGJ/https://security.gentoo.org/glsa/201710-10https://usn.ubuntu.com/3670-1/http://www.openwall.com/lists/oss-security/2017/03/22/1https://blogs.gentoo.org/ago/2016/11/04/elfutils-memory-allocation-failure-in-__libelf_set_rawdata_wrlock-elf_getdata-c/https://bugzilla.redhat.com/show_bug.cgi?id=1387584https://lists.fedorahosted.org/archives/list/elfutils-devel%40lists.fedorahosted.org/thread/Q4LE47FPEVRZANMV6JE2NMHYO4H5MHGJ/https://security.gentoo.org/glsa/201710-10https://usn.ubuntu.com/3670-1/
2017-03-23
Published