CVE-2019-7146

Name
CVE-2019-7146
Description
In elfutils 0.175, there is a buffer over-read in the ebl_object_note function in eblobjnote.c in libebl. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted elf file, as demonstrated by eu-readelf.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Issue Tracking https://sourceware.org/bugzilla/show_bug.cgi?id=24081
Exploit https://sourceware.org/bugzilla/show_bug.cgi?id=24075
REDHAT https://access.redhat.com/errata/RHSA-2019:3575

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:elfutils_project:elfutils:0.175:*:*:*:*:*:*:* elfutils == None == 0.175

Vulnerable and fixed packages

Source package Branch Version Maintainer Status