CVE-2021-33294
published 2023-07-18CVE-2021-33294: In elfutils 0.183, an infinite loop was found in the function handle_symtab in readelf.c .Which allows attackers to cause a denial of service (infinite loop)…
PriorityP415medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.29%
21.4th percentile
In elfutils 0.183, an infinite loop was found in the function handle_symtab in readelf.c .Which allows attackers to cause a denial of service (infinite loop) via crafted file.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | elfutils | < elfutils 0.185-2 (bookworm) | elfutils 0.185-2 (bookworm) |
| elfutils_project | elfutils | — | — |
| elfutils_project | elfutils | >= 0 < 0.185-2 | 0.185-2 |
| elfutils_project | elfutils | >= 0 < 0.185-2 | 0.185-2 |
| elfutils_project | elfutils | >= 0 < 0.185-2 | 0.185-2 |
| elfutils_project | elfutils | >= 0 < 0.176-1.1ubuntu0.1 | 0.176-1.1ubuntu0.1 |
| elfutils_project | elfutils | >= 0 < 0.158-0ubuntu5.3+esm1 | 0.158-0ubuntu5.3+esm1 |
| elfutils_project | elfutils | >= 0 < 0.165-3ubuntu1.2+esm1 | 0.165-3ubuntu1.2+esm1 |
| elfutils_project | elfutils | >= 0 < 0.170-0.4ubuntu0.1+esm1 | 0.170-0.4ubuntu0.1+esm1 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
elfutils vulnerabilities
vendor_ubuntu·2023-08-30·CVSS 5.5
CVE-2021-33294 [MEDIUM] elfutils vulnerabilities
Title: elfutils vulnerabilities
Summary: Several security issues were fixed in elfutils.
It was discovered that elfutils incorrectly handled certain malformed
files. If a user or automated system were tricked into processing a
specially crafted file, elfutils could be made to crash or consume
resources, resulting in a denial of service. This issue only affected
Ubuntu 14.04 LTS. (CVE-2018-16062, CVE-2018-16403, CVE-2018-18310,
CVE-2018-18520, CVE-2018-18521, CVE-2019-7149, CVE-2019-7150,
CVE-2019-7665)
It was discovered that elfutils incorrectly handled bounds checks in
certain functions when processing malformed files. If a user or automated
system were tricked into processing a specially crafted file, elfutils
could be made to crash or consume resources, resulting in a denial of
servi
Red Hat
elfutils: an infinite loop was found in the function handle_symtab in readelf.c which causes denial of service
vendor_redhat·2023-07-18·CVSS 5.5
CVE-2021-33294 [MEDIUM] CWE-400 elfutils: an infinite loop was found in the function handle_symtab in readelf.c which causes denial of service
elfutils: an infinite loop was found in the function handle_symtab in readelf.c which causes denial of service
In elfutils 0.183, an infinite loop was found in the function handle_symtab in readelf.c .Which allows attackers to cause a denial of service (infinite loop) via crafted file.
A flaw was found in the elfutils tools package. An infinite loop is possible in the handle_symtab function in readelf.c, which may lead to a denial of service.
A vulnerability was found in Elfutils, where an infinite loop in the handle_symtab function within readelf.c can lead to a denial of service, causing the application to become unresponsive and consume excessive system resources indefinitely.
Statement: This vulnerability is rated as moderate because an infinite loop in Elfutils' handle_symtab funct
Debian
CVE-2021-33294: elfutils - In elfutils 0.183, an infinite loop was found in the function handle_symtab in r...
vendor_debian·2021·CVSS 5.5
CVE-2021-33294 [MEDIUM] CVE-2021-33294: elfutils - In elfutils 0.183, an infinite loop was found in the function handle_symtab in r...
In elfutils 0.183, an infinite loop was found in the function handle_symtab in readelf.c .Which allows attackers to cause a denial of service (infinite loop) via crafted file.
Scope: local
bookworm: resolved (fixed in 0.185-2)
bullseye: open
forky: resolved (fixed in 0.185-2)
sid: resolved (fixed in 0.185-2)
trixie: resolved (fixed in 0.185-2)
OSV
elfutils vulnerabilities
osv·2023-08-30·CVSS 5.5
CVE-2018-16062 [MEDIUM] elfutils vulnerabilities
elfutils vulnerabilities
It was discovered that elfutils incorrectly handled certain malformed
files. If a user or automated system were tricked into processing a
specially crafted file, elfutils could be made to crash or consume
resources, resulting in a denial of service. This issue only affected
Ubuntu 14.04 LTS. (CVE-2018-16062, CVE-2018-16403, CVE-2018-18310,
CVE-2018-18520, CVE-2018-18521, CVE-2019-7149, CVE-2019-7150,
CVE-2019-7665)
It was discovered that elfutils incorrectly handled bounds checks in
certain functions when processing malformed files. If a user or automated
system were tricked into processing a specially crafted file, elfutils
could be made to crash or consume resources, resulting in a denial of
service. (CVE-2020-21047, CVE-2021-33294)
GHSA
GHSA-827x-xjfm-cw2c: In elfutils 0
ghsa_unreviewed·2023-07-18
CVE-2021-33294 [MEDIUM] CWE-835 GHSA-827x-xjfm-cw2c: In elfutils 0
In elfutils 0.183, an infinite loop was found in the function handle_symtab in readelf.c .Which allows attackers to cause a denial of service (infinite loop) via crafted file.
OSV
CVE-2021-33294: In elfutils 0
osv·2023-07-18·CVSS 5.5
CVE-2021-33294 [MEDIUM] CVE-2021-33294: In elfutils 0
In elfutils 0.183, an infinite loop was found in the function handle_symtab in readelf.c .Which allows attackers to cause a denial of service (infinite loop) via crafted file.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-07-18
Published