Debian Elfutils vulnerabilities
25 known vulnerabilities affecting debian/elfutils.
Total CVEs
25
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM12LOW13
Vulnerabilities
Page 2 of 2
CVE-2018-16403P4LOWCVSS 5.5fixed in elfutils 0.175-1 (bookworm)2018
CVE-2018-16403 [MEDIUM] CVE-2018-16403: elfutils - libdw in elfutils 0.173 checks the end of the attributes list incorrectly in dwa...
libdw in elfutils 0.173 checks the end of the attributes list incorrectly in dwarf_getabbrev in dwarf_getabbrev.c and dwarf_hasattr in dwarf_hasattr.c, leading to a heap-based buffer over-read and an application crash.
Scope: local
bookworm: resolved (fixed in 0.175-1)
bullseye: resolved (fixed in 0.175-1)
forky: resolved (fixed in 0.175-1)
sid: resolved (fixed i
debian
CVE-2019-7664P4LOWCVSS 5.5fixed in elfutils 0.176-1 (bookworm)2019
CVE-2019-7664 [MEDIUM] CVE-2019-7664: elfutils - In elfutils 0.175, a negative-sized memcpy is attempted in elf_cvt_note in libel...
In elfutils 0.175, a negative-sized memcpy is attempted in elf_cvt_note in libelf/note_xlate.h because of an incorrect overflow check. Crafted elf input causes a segmentation fault, leading to denial of service (program crash).
Scope: local
bookworm: resolved (fixed in 0.176-1)
bullseye: resolved (fixed in 0.176-1)
forky: resolved (fixed in 0.176-1)
sid: resolved (
debian
CVE-2018-18521P4LOWCVSS 5.5fixed in elfutils 0.175-1 (bookworm)2018
CVE-2018-18521 [MEDIUM] CVE-2018-18521: elfutils - Divide-by-zero vulnerabilities in the function arlib_add_symbols() in arlib.c in...
Divide-by-zero vulnerabilities in the function arlib_add_symbols() in arlib.c in elfutils 0.174 allow remote attackers to cause a denial of service (application crash) with a crafted ELF file, as demonstrated by eu-ranlib, because a zero sh_entsize is mishandled.
Scope: local
bookworm: resolved (fixed in 0.175-1)
bullseye: resolved (fixed in 0.175-1)
forky: resol
debian
CVE-2021-33294P4LOWCVSS 5.5fixed in elfutils 0.185-2 (bookworm)2021
CVE-2021-33294 [MEDIUM] CVE-2021-33294: elfutils - In elfutils 0.183, an infinite loop was found in the function handle_symtab in r...
In elfutils 0.183, an infinite loop was found in the function handle_symtab in readelf.c .Which allows attackers to cause a denial of service (infinite loop) via crafted file.
Scope: local
bookworm: resolved (fixed in 0.185-2)
bullseye: open
forky: resolved (fixed in 0.185-2)
sid: resolved (fixed in 0.185-2)
trixie: resolved (fixed in 0.185-2)
debian
CVE-2018-18310P4MEDIUMCVSS 5.5fixed in elfutils 0.175-1 (bookworm)2018
CVE-2018-18310 [MEDIUM] CVE-2018-18310: elfutils - An invalid memory address dereference was discovered in dwfl_segment_report_modu...
An invalid memory address dereference was discovered in dwfl_segment_report_module.c in libdwfl in elfutils through v0.174. The vulnerability allows attackers to cause a denial of service (application crash) with a crafted ELF file, as demonstrated by consider_notes.
Scope: local
bookworm: resolved (fixed in 0.175-1)
bullseye: resolved (fixed in 0.175-1)
forky: r
debian
← Previous2 / 2