CVE-2017-7607
published 2017-04-09CVE-2017-7607: The handle_gnu_hash function in readelf.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application…
PriorityP420medium5.5CVSS 3.0
AVLACLPRNUIRSUCNINAH
EPSS
1.70%
74.4th percentile
The handle_gnu_hash function in readelf.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | elfutils | < elfutils 0.168-1 (bookworm) | elfutils 0.168-1 (bookworm) |
| elfutils_project | elfutils | — | — |
| elfutils_project | elfutils | >= 0 < 0.168-1 | 0.168-1 |
| elfutils_project | elfutils | >= 0 < 0.168-1 | 0.168-1 |
| elfutils_project | elfutils | >= 0 < 0.168-1 | 0.168-1 |
| elfutils_project | elfutils | >= 0 < 0.168-1 | 0.168-1 |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
elfutils vulnerabilities
vendor_ubuntu·2018-06-05
CVE-2016-10254 elfutils vulnerabilities
Title: elfutils vulnerabilities
Summary: elfutils could be made to crash or consume resources if it opened a
specially crafted file.
Agostino Sarubbo discovered that elfutils incorrectly handled certain
malformed ELF files. If a user or automated system were tricked into
processing a specially crafted ELF file, elfutils could be made to crash or
consume resources, resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
elfutils: Heap-buffer overflow in the handle_gnu_hash function
vendor_redhat·2017-04-04·CVSS 5.5
CVE-2017-7607 [MEDIUM] CWE-122 elfutils: Heap-buffer overflow in the handle_gnu_hash function
elfutils: Heap-buffer overflow in the handle_gnu_hash function
The handle_gnu_hash function in readelf.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file.
Package: elfutils (Red Hat Enterprise Linux 5) - Will not fix
Package: elfutils (Red Hat Enterprise Linux 6) - Will not fix
Package: elfutils (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2017-7607: elfutils - The handle_gnu_hash function in readelf.c in elfutils 0.168 allows remote attack...
vendor_debian·2017·CVSS 5.5
CVE-2017-7607 [MEDIUM] CVE-2017-7607: elfutils - The handle_gnu_hash function in readelf.c in elfutils 0.168 allows remote attack...
The handle_gnu_hash function in readelf.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file.
Scope: local
bookworm: resolved (fixed in 0.168-1)
bullseye: resolved (fixed in 0.168-1)
forky: resolved (fixed in 0.168-1)
sid: resolved (fixed in 0.168-1)
trixie: resolved (fixed in 0.168-1)
GHSA
GHSA-78hq-848f-rjwp: The handle_gnu_hash function in readelf
ghsa_unreviewed·2022-05-13
CVE-2017-7607 [MEDIUM] CWE-125 GHSA-78hq-848f-rjwp: The handle_gnu_hash function in readelf
The handle_gnu_hash function in readelf.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file.
OSV
CVE-2017-7607: The handle_gnu_hash function in readelf
osv·2017-04-09·CVSS 5.5
CVE-2017-7607 [MEDIUM] CVE-2017-7607: The handle_gnu_hash function in readelf
The handle_gnu_hash function in readelf.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-7607 CVE-2017-7608 CVE-2017-7609 CVE-2017-7610 CVE-2017-7611 CVE-2017-7612 CVE-2017-7613 elfutils: various flaws [fedora-all]
bugzilla·2017-04-12·CVSS 5.5
CVE-2017-7607 [MEDIUM] CVE-2017-7607 CVE-2017-7608 CVE-2017-7609 CVE-2017-7610 CVE-2017-7611 CVE-2017-7612 CVE-2017-7613 elfutils: various flaws [fedora-all]
CVE-2017-7607 CVE-2017-7608 CVE-2017-7609 CVE-2017-7610 CVE-2017-7611 CVE-2017-7612 CVE-2017-7613 elfutils: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit messa
Bugzilla
CVE-2017-7607 elfutils: Heap-buffer overflow in the handle_gnu_hash function
bugzilla·2017-04-12·CVSS 5.5
CVE-2017-7607 [MEDIUM] CVE-2017-7607 elfutils: Heap-buffer overflow in the handle_gnu_hash function
CVE-2017-7607 elfutils: Heap-buffer overflow in the handle_gnu_hash function
The handle_gnu_hash function in readelf.c in elfutils allows attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file.
Upstream bug:
https://sourceware.org/bugzilla/show_bug.cgi?id=21299
Upstream patch:
https://sourceware.org/ml/elfutils-devel/2017-q1/msg00109.html
References:
https://blogs.gentoo.org/ago/2017/04/03/elfutils-heap-based-buffer-overflow-in-handle_gnu_hash-readelf-c/
Discussion:
Created elfutils tracking bugs for this issue:
Affects: fedora-all [bug 1441630]
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00052.htmlhttp://www.securityfocus.com/bid/98608https://blogs.gentoo.org/ago/2017/04/03/elfutils-heap-based-buffer-overflow-in-handle_gnu_hash-readelf-chttps://security.gentoo.org/glsa/201710-10https://usn.ubuntu.com/3670-1/http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00052.htmlhttp://www.securityfocus.com/bid/98608https://blogs.gentoo.org/ago/2017/04/03/elfutils-heap-based-buffer-overflow-in-handle_gnu_hash-readelf-chttps://security.gentoo.org/glsa/201710-10https://usn.ubuntu.com/3670-1/
2017-04-09
Published