cbcvebase.

Debian Elfutils vulnerabilities

25 known vulnerabilities affecting debian/elfutils.

Total CVEs
25
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM12LOW13

Vulnerabilities

Page 2 of 2
CVE-2018-16403P4LOWCVSS 5.5fixed in elfutils 0.175-1 (bookworm)2018
CVE-2018-16403 [MEDIUM] CVE-2018-16403: elfutils - libdw in elfutils 0.173 checks the end of the attributes list incorrectly in dwa... libdw in elfutils 0.173 checks the end of the attributes list incorrectly in dwarf_getabbrev in dwarf_getabbrev.c and dwarf_hasattr in dwarf_hasattr.c, leading to a heap-based buffer over-read and an application crash. Scope: local bookworm: resolved (fixed in 0.175-1) bullseye: resolved (fixed in 0.175-1) forky: resolved (fixed in 0.175-1) sid: resolved (fixed i
debian
CVE-2019-7664P4LOWCVSS 5.5fixed in elfutils 0.176-1 (bookworm)2019
CVE-2019-7664 [MEDIUM] CVE-2019-7664: elfutils - In elfutils 0.175, a negative-sized memcpy is attempted in elf_cvt_note in libel... In elfutils 0.175, a negative-sized memcpy is attempted in elf_cvt_note in libelf/note_xlate.h because of an incorrect overflow check. Crafted elf input causes a segmentation fault, leading to denial of service (program crash). Scope: local bookworm: resolved (fixed in 0.176-1) bullseye: resolved (fixed in 0.176-1) forky: resolved (fixed in 0.176-1) sid: resolved (
debian
CVE-2018-18521P4LOWCVSS 5.5fixed in elfutils 0.175-1 (bookworm)2018
CVE-2018-18521 [MEDIUM] CVE-2018-18521: elfutils - Divide-by-zero vulnerabilities in the function arlib_add_symbols() in arlib.c in... Divide-by-zero vulnerabilities in the function arlib_add_symbols() in arlib.c in elfutils 0.174 allow remote attackers to cause a denial of service (application crash) with a crafted ELF file, as demonstrated by eu-ranlib, because a zero sh_entsize is mishandled. Scope: local bookworm: resolved (fixed in 0.175-1) bullseye: resolved (fixed in 0.175-1) forky: resol
debian
CVE-2021-33294P4LOWCVSS 5.5fixed in elfutils 0.185-2 (bookworm)2021
CVE-2021-33294 [MEDIUM] CVE-2021-33294: elfutils - In elfutils 0.183, an infinite loop was found in the function handle_symtab in r... In elfutils 0.183, an infinite loop was found in the function handle_symtab in readelf.c .Which allows attackers to cause a denial of service (infinite loop) via crafted file. Scope: local bookworm: resolved (fixed in 0.185-2) bullseye: open forky: resolved (fixed in 0.185-2) sid: resolved (fixed in 0.185-2) trixie: resolved (fixed in 0.185-2)
debian
CVE-2018-18310P4MEDIUMCVSS 5.5fixed in elfutils 0.175-1 (bookworm)2018
CVE-2018-18310 [MEDIUM] CVE-2018-18310: elfutils - An invalid memory address dereference was discovered in dwfl_segment_report_modu... An invalid memory address dereference was discovered in dwfl_segment_report_module.c in libdwfl in elfutils through v0.174. The vulnerability allows attackers to cause a denial of service (application crash) with a crafted ELF file, as demonstrated by consider_notes. Scope: local bookworm: resolved (fixed in 0.175-1) bullseye: resolved (fixed in 0.175-1) forky: r
debian
Debian Elfutils vulnerabilities | cvebase