CVE-2018-16403

CWE-125Out-of-bounds Read11 documents8 sources
Severity
5.5MEDIUM
EPSS
0.1%
top 71.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 3
Latest updateAug 30

Description

libdw in elfutils 0.173 checks the end of the attributes list incorrectly in dwarf_getabbrev in dwarf_getabbrev.c and dwarf_hasattr in dwarf_hasattr.c, leading to a heap-based buffer over-read and an application crash.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages3 packages

Debianelfutils< 0.175-1+3
Ubuntuelfutils< 0.176-1.1ubuntu0.1+3

🔴Vulnerability Details

4
OSV
elfutils vulnerabilities2023-08-30
GHSA
GHSA-4v8w-v3fq-rj46: libdw in elfutils 02022-05-13
OSV
CVE-2018-16403: libdw in elfutils 02018-09-03
CVEList
CVE-2018-16403: libdw in elfutils 02018-09-03

📋Vendor Advisories

4
Ubuntu
elfutils vulnerabilities2023-08-30
Ubuntu
elfutils vulnerabilities2019-06-10
Red Hat
elfutils: Heap-based buffer over-read in libdw/dwarf_getabbrev.c and libwd/dwarf_hasattr.c causes crash2018-08-15
Debian
CVE-2018-16403: elfutils - libdw in elfutils 0.173 checks the end of the attributes list incorrectly in dwa...2018

💬Community

2
Bugzilla
CVE-2018-16403 elfutils: Heap-based buffer over-read in libdw/dwarf_getabbrev.c and libwd/dwarf_hasattr.c causes crash2018-09-04
Bugzilla
CVE-2018-16403 elfutils: Heap-based buffer over-read in libdw/dwarf_getabbrev.c and libwd/dwarf_hasattr.c causes crash [fedora-all]2018-09-04