Lucene search

K
ubuntuUbuntuUSN-6322-1
HistoryAug 30, 2023 - 12:00 a.m.

elfutils vulnerabilities

2023-08-3000:00:00
ubuntu.com
27
ubuntu
elfutils
vulnerabilities
denial of service
malformed files
bounds checks
esm
lts
resource consumption
cve

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

7 High

AI Score

Confidence

High

0.006 Low

EPSS

Percentile

78.0%

Releases

  • Ubuntu 20.04 LTS
  • Ubuntu 18.04 ESM
  • Ubuntu 16.04 ESM
  • Ubuntu 14.04 ESM

Packages

  • elfutils - collection of utilities to handle ELF objects

Details

It was discovered that elfutils incorrectly handled certain malformed
files. If a user or automated system were tricked into processing a
specially crafted file, elfutils could be made to crash or consume
resources, resulting in a denial of service. This issue only affected
Ubuntu 14.04 LTS. (CVE-2018-16062, CVE-2018-16403, CVE-2018-18310,
CVE-2018-18520, CVE-2018-18521, CVE-2019-7149, CVE-2019-7150,
CVE-2019-7665)

It was discovered that elfutils incorrectly handled bounds checks in
certain functions when processing malformed files. If a user or automated
system were tricked into processing a specially crafted file, elfutils
could be made to crash or consume resources, resulting in a denial of
service. (CVE-2020-21047, CVE-2021-33294)

OSVersionArchitecturePackageVersionFilename
Ubuntu20.04noarchelfutils< 0.176-1.1ubuntu0.1UNKNOWN
Ubuntu20.04noarchelfutils-dbgsym< 0.176-1.1ubuntu0.1UNKNOWN
Ubuntu20.04noarchlibasm-dev< 0.176-1.1ubuntu0.1UNKNOWN
Ubuntu20.04noarchlibasm1< 0.176-1.1ubuntu0.1UNKNOWN
Ubuntu20.04noarchlibasm1-dbgsym< 0.176-1.1ubuntu0.1UNKNOWN
Ubuntu20.04noarchlibdw-dev< 0.176-1.1ubuntu0.1UNKNOWN
Ubuntu20.04noarchlibdw1< 0.176-1.1ubuntu0.1UNKNOWN
Ubuntu20.04noarchlibdw1-dbgsym< 0.176-1.1ubuntu0.1UNKNOWN
Ubuntu20.04noarchlibelf-dev< 0.176-1.1ubuntu0.1UNKNOWN
Ubuntu20.04noarchlibelf1< 0.176-1.1ubuntu0.1UNKNOWN
Rows per page:
1-10 of 561

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:N/I:N/A:P

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

7 High

AI Score

Confidence

High

0.006 Low

EPSS

Percentile

78.0%