CVE-2025-1377

Name
CVE-2025-1377
Description
A vulnerability, which was classified as problematic, has been found in GNU elfutils 0.192. This issue affects the function gelf_getsymshndx of the file strip.c of the component eu-strip. The manipulation leads to denial of service. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The identifier of the patch is fbf1df9ca286de3323ae541973b08449f8d03aba. It is recommended to apply a patch to fix this issue.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
exploit https://sourceware.org/bugzilla/attachment.cgi?id=15941
issue-tracking https://sourceware.org/bugzilla/show_bug.cgi?id=32673
issue-tracking https://sourceware.org/bugzilla/show_bug.cgi?id=32673#c2
signature https://vuldb.com/?ctiid.295985
vdb-entry https://vuldb.com/?id.295985
third-party-advisory https://vuldb.com/?submit.497539
product https://www.gnu.org/

Match rules

CPE URI Source package Min version Max version
elfutils == 0.192 == 0.192

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
elfutils edge-main 0.192-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable