CVE-2020-21047
published 2023-08-22CVE-2020-21047: The libcpu component which is used by libasm of elfutils version 0.177 (git 47780c9e), suffers from denial-of-service vulnerability caused by application…
PriorityP420medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.23%
13.3th percentile
The libcpu component which is used by libasm of elfutils version 0.177 (git 47780c9e), suffers from denial-of-service vulnerability caused by application crashes due to out-of-bounds write (CWE-787), off-by-one error (CWE-193) and reachable assertion (CWE-617); to exploit the vulnerability, the attackers need to craft certain ELF files which bypass the missing bound checks.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | elfutils | < elfutils 0.180-1 (bookworm) | elfutils 0.180-1 (bookworm) |
| elfutils_project | elfutils | — | — |
| elfutils_project | elfutils | >= 0 < 0.180-1 | 0.180-1 |
| elfutils_project | elfutils | >= 0 < 0.180-1 | 0.180-1 |
| elfutils_project | elfutils | >= 0 < 0.180-1 | 0.180-1 |
| elfutils_project | elfutils | >= 0 < 0.180-1 | 0.180-1 |
| elfutils_project | elfutils | >= 0 < 0.176-1.1ubuntu0.1 | 0.176-1.1ubuntu0.1 |
| elfutils_project | elfutils | >= 0 < 0.158-0ubuntu5.3+esm1 | 0.158-0ubuntu5.3+esm1 |
| elfutils_project | elfutils | >= 0 < 0.165-3ubuntu1.2+esm1 | 0.165-3ubuntu1.2+esm1 |
| elfutils_project | elfutils | >= 0 < 0.170-0.4ubuntu0.1+esm1 | 0.170-0.4ubuntu0.1+esm1 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
cisa_ics·2023-12-14
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
ICS Advisory
##
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
Release DateDecember 14, 2023
Alert CodeICSA-23-348-10
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
- Vulnerabilities: Improper Restriction of XML External Entity Reference, Time-of-check Time-of-use (TOCTOU) Race Condition, Command Injection, Miss
Ubuntu
elfutils vulnerabilities
vendor_ubuntu·2023-08-30·CVSS 5.5
CVE-2021-33294 [MEDIUM] elfutils vulnerabilities
Title: elfutils vulnerabilities
Summary: Several security issues were fixed in elfutils.
It was discovered that elfutils incorrectly handled certain malformed
files. If a user or automated system were tricked into processing a
specially crafted file, elfutils could be made to crash or consume
resources, resulting in a denial of service. This issue only affected
Ubuntu 14.04 LTS. (CVE-2018-16062, CVE-2018-16403, CVE-2018-18310,
CVE-2018-18520, CVE-2018-18521, CVE-2019-7149, CVE-2019-7150,
CVE-2019-7665)
It was discovered that elfutils incorrectly handled bounds checks in
certain functions when processing malformed files. If a user or automated
system were tricked into processing a specially crafted file, elfutils
could be made to crash or consume resources, resulting in a denial of
servi
Debian
CVE-2020-21047: elfutils - The libcpu component which is used by libasm of elfutils version 0.177 (git 4778...
vendor_debian·2020·CVSS 5.5
CVE-2020-21047 [MEDIUM] CVE-2020-21047: elfutils - The libcpu component which is used by libasm of elfutils version 0.177 (git 4778...
The libcpu component which is used by libasm of elfutils version 0.177 (git 47780c9e), suffers from denial-of-service vulnerability caused by application crashes due to out-of-bounds write (CWE-787), off-by-one error (CWE-193) and reachable assertion (CWE-617); to exploit the vulnerability, the attackers need to craft certain ELF files which bypass the missing bound checks.
Scope: local
bookworm: resolved (fixed in 0.180-1)
bullseye: resolved (fixed in 0.180-1)
forky: resolved (fixed in 0.180-1)
sid: resolved (fixed in 0.180-1)
trixie: resolved (fixed in 0.180-1)
OSV
elfutils vulnerabilities
osv·2023-08-30·CVSS 5.5
CVE-2018-16062 [MEDIUM] elfutils vulnerabilities
elfutils vulnerabilities
It was discovered that elfutils incorrectly handled certain malformed
files. If a user or automated system were tricked into processing a
specially crafted file, elfutils could be made to crash or consume
resources, resulting in a denial of service. This issue only affected
Ubuntu 14.04 LTS. (CVE-2018-16062, CVE-2018-16403, CVE-2018-18310,
CVE-2018-18520, CVE-2018-18521, CVE-2019-7149, CVE-2019-7150,
CVE-2019-7665)
It was discovered that elfutils incorrectly handled bounds checks in
certain functions when processing malformed files. If a user or automated
system were tricked into processing a specially crafted file, elfutils
could be made to crash or consume resources, resulting in a denial of
service. (CVE-2020-21047, CVE-2021-33294)
GHSA
GHSA-q33x-5cf5-cqqv: The libcpu component which is used by libasm of elfutils version 0
ghsa_unreviewed·2023-08-22
CVE-2020-21047 [MEDIUM] CWE-787 GHSA-q33x-5cf5-cqqv: The libcpu component which is used by libasm of elfutils version 0
The libcpu component which is used by libasm of elfutils version 0.177 (git 47780c9e), suffers from denial-of-service vulnerability caused by application crashes due to out-of-bounds write (CWE-787), off-by-one error (CWE-193) and reachable assertion (CWE-617); to exploit the vulnerability, the attackers need to craft certain ELF files which bypass the missing bound checks.
OSV
CVE-2020-21047: The libcpu component which is used by libasm of elfutils version 0
osv·2023-08-22·CVSS 5.5
CVE-2020-21047 [MEDIUM] CVE-2020-21047: The libcpu component which is used by libasm of elfutils version 0
The libcpu component which is used by libasm of elfutils version 0.177 (git 47780c9e), suffers from denial-of-service vulnerability caused by application crashes due to out-of-bounds write (CWE-787), off-by-one error (CWE-193) and reachable assertion (CWE-617); to exploit the vulnerability, the attackers need to craft certain ELF files which bypass the missing bound checks.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://lists.debian.org/debian-lts-announce/2023/09/msg00026.htmlhttps://sourceware.org/bugzilla/show_bug.cgi?id=25068https://sourceware.org/git/?p=elfutils.git%3Ba=commitdiff%3Bh=99dc63b10b3878616b85df2dfd2e4e7103e414b8https://lists.debian.org/debian-lts-announce/2023/09/msg00026.htmlhttps://sourceware.org/bugzilla/show_bug.cgi?id=25068https://sourceware.org/git/?p=elfutils.git%3Ba=commitdiff%3Bh=99dc63b10b3878616b85df2dfd2e4e7103e414b8
2023-08-22
Published