CVE-2018-16402
published 2018-09-03CVE-2018-16402: libelf/elf_end.c in elfutils 0.173 allows remote attackers to cause a denial of service (double free and application crash) or possibly have unspecified other…
PriorityP341critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
3.69%
88.5th percentile
libelf/elf_end.c in elfutils 0.173 allows remote attackers to cause a denial of service (double free and application crash) or possibly have unspecified other impact because it tries to decompress twice.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | elfutils | < elfutils 0.175-1 (bookworm) | elfutils 0.175-1 (bookworm) |
| elfutils_project | elfutils | — | — |
| elfutils_project | elfutils | >= 0 < 0.175-1 | 0.175-1 |
| elfutils_project | elfutils | >= 0 < 0.175-1 | 0.175-1 |
| elfutils_project | elfutils | >= 0 < 0.175-1 | 0.175-1 |
| elfutils_project | elfutils | >= 0 < 0.175-1 | 0.175-1 |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
| paloalto | pan-os | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8LOW
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN
vendor_paloalto·2020-07-08·CVSS 9.8
CVE-2013-7459 [CRITICAL] PAN
PAN
The Palo Alto Networks Product Security Assurance team has evaluated and determined that these third-party or open source vulnerabilities do not have any security impact on PAN-OS or that the scenarios required for successful
CVEs: CVE-2013-7459, CVE-2018-1120, CVE-2018-1121, CVE-2018-1122, CVE-2018-1123, CVE-2018-1124, CVE-2018-16402, CVE-2020-11022, CVE-2020-11023, CVE-2020-11896, CVE-2020-11897, CVE-2020-11898, CVE-2020-11899, CVE-2020-11900, CVE-2020-11901, CVE-2020-11902, CVE-2020-11903, CVE-2020-11904, CVE-2020-11905, CVE-2020-11906, CVE-2020-11907, CVE-2020-11908, CVE-2020-11909, CVE-2020-11910, CVE-2020-11911, CVE-2020-11912, CVE-2020-11913, CVE-2020-11914
Affected products: PAN-OS
Ubuntu
elfutils vulnerabilities
vendor_ubuntu·2019-06-10
CVE-2018-16062 elfutils vulnerabilities
Title: elfutils vulnerabilities
Summary: Several security issues were fixed in elfutils.
It was discovered that elfutils incorrectly handled certain malformed
files. If a user or automated system were tricked into processing a
specially crafted file, elfutils could be made to crash or consume
resources, resulting in a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
elfutils: Double-free due to double decompression of sections in crafted ELF causes crash
vendor_redhat·2018-08-15·CVSS 9.8
CVE-2018-16402 [CRITICAL] CWE-416 elfutils: Double-free due to double decompression of sections in crafted ELF causes crash
elfutils: Double-free due to double decompression of sections in crafted ELF causes crash
libelf/elf_end.c in elfutils 0.173 allows remote attackers to cause a denial of service (double free and application crash) or possibly have unspecified other impact because it tries to decompress twice.
Package: elfutils (Red Hat Enterprise Linux 5) - Not affected
Package: elfutils (Red Hat Enterprise Linux 6) - Not affected
Package: elfutils (Red Hat Enterprise Linux 8) - Not affected
Package: elfutils (Red Hat Virtualization 4) - Will not fix
Debian
CVE-2018-16402: elfutils - libelf/elf_end.c in elfutils 0.173 allows remote attackers to cause a denial of ...
vendor_debian·2018·CVSS 9.8
CVE-2018-16402 [CRITICAL] CVE-2018-16402: elfutils - libelf/elf_end.c in elfutils 0.173 allows remote attackers to cause a denial of ...
libelf/elf_end.c in elfutils 0.173 allows remote attackers to cause a denial of service (double free and application crash) or possibly have unspecified other impact because it tries to decompress twice.
Scope: local
bookworm: resolved (fixed in 0.175-1)
bullseye: resolved (fixed in 0.175-1)
forky: resolved (fixed in 0.175-1)
sid: resolved (fixed in 0.175-1)
trixie: resolved (fixed in 0.175-1)
GHSA
GHSA-c337-vg7c-wfqh: libelf/elf_end
ghsa_unreviewed·2022-05-13
CVE-2018-16402 [CRITICAL] CWE-415 GHSA-c337-vg7c-wfqh: libelf/elf_end
libelf/elf_end.c in elfutils 0.173 allows remote attackers to cause a denial of service (double free and application crash) or possibly have unspecified other impact because it tries to decompress twice.
OSV
CVE-2018-16402: libelf/elf_end
osv·2018-09-03·CVSS 9.8
CVE-2018-16402 [CRITICAL] CVE-2018-16402: libelf/elf_end
libelf/elf_end.c in elfutils 0.173 allows remote attackers to cause a denial of service (double free and application crash) or possibly have unspecified other impact because it tries to decompress twice.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-16402 elfutils: Double-free due to double decompression of sections in crafted ELF causes crash [fedora-all]
bugzilla·2018-09-04·CVSS 9.8
CVE-2018-16402 [CRITICAL] CVE-2018-16402 elfutils: Double-free due to double decompression of sections in crafted ELF causes crash [fedora-all]
CVE-2018-16402 elfutils: Double-free due to double decompression of sections in crafted ELF causes crash [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this i
Bugzilla
CVE-2018-16402 elfutils: Double-free due to double decompression of sections in crafted ELF causes crash
bugzilla·2018-09-04·CVSS 9.8
CVE-2018-16402 [CRITICAL] CVE-2018-16402 elfutils: Double-free due to double decompression of sections in crafted ELF causes crash
CVE-2018-16402 elfutils: Double-free due to double decompression of sections in crafted ELF causes crash
Elfutils through version 0.173 is vulnerable to a double-free in the libelf/elf_end.c:elf_end() function due to the decompression of section data multiple times.. An attacker could exploit this to cause a crash or possibly have unspecified other impact via a crafted ELF.
Upstream Bug:
https://sourceware.org/bugzilla/show_bug.cgi?id=23528
Upstream Patch:
https://sourceware.org/git/?p=elfutils.git;a=patch;h=56b18521fb8d46d40fc090c0de9d11a08bc982fa
Discussion:
Created elfutils tracking bugs for this issue:
Affects: fedora-all [bug 1625051]
---
Reproduced on 7+ quite easily. Did not reproduce on 5/6. 6 was running 0.164.
---
(In reply to Scott Gayou from comment #4)
> Reproduc
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00052.htmlhttps://access.redhat.com/errata/RHSA-2019:2197https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2021/10/msg00030.htmlhttps://sourceware.org/bugzilla/show_bug.cgi?id=23528https://usn.ubuntu.com/4012-1/http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00052.htmlhttps://access.redhat.com/errata/RHSA-2019:2197https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0%40%3Cissues.bookkeeper.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2021/10/msg00030.htmlhttps://sourceware.org/bugzilla/show_bug.cgi?id=23528https://usn.ubuntu.com/4012-1/
2018-09-03
Published