CVE-2017-7613Improper Input Validation in Project Elfutils

Severity
5.5MEDIUMNVD
EPSS
0.6%
top 30.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 9
Latest updateMay 14

Description

elflint.c in elfutils 0.168 does not validate the number of sections and the number of segments, which allows remote attackers to cause a denial of service (memory consumption) via a crafted ELF file.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

Also affects: Debian Linux 8.0, Ubuntu Linux 14.04, 16.04

Patches

🔴Vulnerability Details

3
GHSA
GHSA-f928-x7g5-gh7v: elflint2022-05-14
CVEList
CVE-2017-7613: elflint2017-04-09
OSV
CVE-2017-7613: elflint2017-04-09

📋Vendor Advisories

3
Ubuntu
elfutils vulnerabilities2018-06-05
Red Hat
elfutils: elflint.c does not validate the number of sections and segments2017-04-04
Debian
CVE-2017-7613: elfutils - elflint.c in elfutils 0.168 does not validate the number of sections and the num...2017

💬Community

2
Bugzilla
CVE-2017-7607 CVE-2017-7608 CVE-2017-7609 CVE-2017-7610 CVE-2017-7611 CVE-2017-7612 CVE-2017-7613 elfutils: various flaws [fedora-all]2017-04-12
Bugzilla
CVE-2017-7613 elfutils: elflint.c does not validate the number of sections and segments2017-04-12
CVE-2017-7613 — Improper Input Validation | cvebase