CVE-2017-7609Improper Input Validation in Project Elfutils

Severity
5.5MEDIUMNVD
EPSS
0.5%
top 35.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 9
Latest updateMay 14

Description

elf_compress.c in elfutils 0.168 does not validate the zlib compression factor, which allows remote attackers to cause a denial of service (memory consumption) via a crafted ELF file.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

Patches

🔴Vulnerability Details

3
GHSA
GHSA-5q28-cp33-8xjc: elf_compress2022-05-14
CVEList
CVE-2017-7609: elf_compress2017-04-09
OSV
CVE-2017-7609: elf_compress2017-04-09

📋Vendor Advisories

3
Ubuntu
elfutils vulnerabilities2018-06-05
Red Hat
elfutils: Memory allocation failure in elf_compress.c2017-04-04
Debian
CVE-2017-7609: elfutils - elf_compress.c in elfutils 0.168 does not validate the zlib compression factor, ...2017

💬Community

2
Bugzilla
CVE-2017-7607 CVE-2017-7608 CVE-2017-7609 CVE-2017-7610 CVE-2017-7611 CVE-2017-7612 CVE-2017-7613 elfutils: various flaws [fedora-all]2017-04-12
Bugzilla
CVE-2017-7609 elfutils: Memory allocation failure in elf_compress.c2017-04-12
CVE-2017-7609 — Improper Input Validation | cvebase