CVE-2017-7613
published 2017-04-09CVE-2017-7613: elflint.c in elfutils 0.168 does not validate the number of sections and the number of segments, which allows remote attackers to cause a denial of service…
PriorityP421medium5.5CVSS 3.0
AVLACLPRNUIRSUCNINAH
EPSS
1.70%
74.7th percentile
elflint.c in elfutils 0.168 does not validate the number of sections and the number of segments, which allows remote attackers to cause a denial of service (memory consumption) via a crafted ELF file.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | elfutils | < elfutils 0.168-1 (bookworm) | elfutils 0.168-1 (bookworm) |
| elfutils_project | elfutils | — | — |
| elfutils_project | elfutils | >= 0 < 0.168-1 | 0.168-1 |
| elfutils_project | elfutils | >= 0 < 0.168-1 | 0.168-1 |
| elfutils_project | elfutils | >= 0 < 0.168-1 | 0.168-1 |
| elfutils_project | elfutils | >= 0 < 0.168-1 | 0.168-1 |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f928-x7g5-gh7v: elflint
ghsa_unreviewed·2022-05-14
CVE-2017-7613 [MEDIUM] CWE-20 GHSA-f928-x7g5-gh7v: elflint
elflint.c in elfutils 0.168 does not validate the number of sections and the number of segments, which allows remote attackers to cause a denial of service (memory consumption) via a crafted ELF file.
OSV
CVE-2017-7613: elflint
osv·2017-04-09·CVSS 5.5
CVE-2017-7613 [MEDIUM] CVE-2017-7613: elflint
elflint.c in elfutils 0.168 does not validate the number of sections and the number of segments, which allows remote attackers to cause a denial of service (memory consumption) via a crafted ELF file.
Ubuntu
elfutils vulnerabilities
vendor_ubuntu·2018-06-05
CVE-2016-10254 elfutils vulnerabilities
Title: elfutils vulnerabilities
Summary: elfutils could be made to crash or consume resources if it opened a
specially crafted file.
Agostino Sarubbo discovered that elfutils incorrectly handled certain
malformed ELF files. If a user or automated system were tricked into
processing a specially crafted ELF file, elfutils could be made to crash or
consume resources, resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
elfutils: elflint.c does not validate the number of sections and segments
vendor_redhat·2017-04-04·CVSS 5.5
CVE-2017-7613 [MEDIUM] CWE-20 elfutils: elflint.c does not validate the number of sections and segments
elfutils: elflint.c does not validate the number of sections and segments
elflint.c in elfutils 0.168 does not validate the number of sections and the number of segments, which allows remote attackers to cause a denial of service (memory consumption) via a crafted ELF file.
Package: elfutils (Red Hat Enterprise Linux 5) - Will not fix
Package: elfutils (Red Hat Enterprise Linux 6) - Will not fix
Package: elfutils (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2017-7613: elfutils - elflint.c in elfutils 0.168 does not validate the number of sections and the num...
vendor_debian·2017·CVSS 5.5
CVE-2017-7613 [MEDIUM] CVE-2017-7613: elfutils - elflint.c in elfutils 0.168 does not validate the number of sections and the num...
elflint.c in elfutils 0.168 does not validate the number of sections and the number of segments, which allows remote attackers to cause a denial of service (memory consumption) via a crafted ELF file.
Scope: local
bookworm: resolved (fixed in 0.168-1)
bullseye: resolved (fixed in 0.168-1)
forky: resolved (fixed in 0.168-1)
sid: resolved (fixed in 0.168-1)
trixie: resolved (fixed in 0.168-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-7607 CVE-2017-7608 CVE-2017-7609 CVE-2017-7610 CVE-2017-7611 CVE-2017-7612 CVE-2017-7613 elfutils: various flaws [fedora-all]
bugzilla·2017-04-12·CVSS 5.5
CVE-2017-7607 [MEDIUM] CVE-2017-7607 CVE-2017-7608 CVE-2017-7609 CVE-2017-7610 CVE-2017-7611 CVE-2017-7612 CVE-2017-7613 elfutils: various flaws [fedora-all]
CVE-2017-7607 CVE-2017-7608 CVE-2017-7609 CVE-2017-7610 CVE-2017-7611 CVE-2017-7612 CVE-2017-7613 elfutils: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit messa
Bugzilla
CVE-2017-7613 elfutils: elflint.c does not validate the number of sections and segments
bugzilla·2017-04-12·CVSS 5.5
CVE-2017-7613 [MEDIUM] CVE-2017-7613 elfutils: elflint.c does not validate the number of sections and segments
CVE-2017-7613 elfutils: elflint.c does not validate the number of sections and segments
elflint.c in elfutils does not validate the number of sections and the number of segments, which allows attackers to cause a denial of service (memory consumption) via a crafted ELF file.
Upstream bug:
https://sourceware.org/bugzilla/show_bug.cgi?id=21312
Upstream patch:
https://sourceware.org/ml/elfutils-devel/2017-q1/msg00133.html
References:
https://blogs.gentoo.org/ago/2017/04/03/elfutils-memory-allocation-failure-in-xcalloc-xmalloc-c/
Discussion:
Created elfutils tracking bugs for this issue:
Affects: fedora-all [bug 1441630]
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00052.htmlhttps://blogs.gentoo.org/ago/2017/04/03/elfutils-memory-allocation-failure-in-xcalloc-xmalloc-chttps://lists.debian.org/debian-lts-announce/2019/02/msg00036.htmlhttps://security.gentoo.org/glsa/201710-10https://usn.ubuntu.com/3670-1/http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00052.htmlhttps://blogs.gentoo.org/ago/2017/04/03/elfutils-memory-allocation-failure-in-xcalloc-xmalloc-chttps://lists.debian.org/debian-lts-announce/2019/02/msg00036.htmlhttps://security.gentoo.org/glsa/201710-10https://usn.ubuntu.com/3670-1/
2017-04-09
Published