跳转到帖子

Ubuntu: USN-6322-1 (CVE-2020-21047): elfutils vulnerabilities

recommended_posts

发布于
  • Members

Ubuntu: USN-6322-1 (CVE-2020-21047): elfutils vulnerabilities

Severity
5
CVSS
(AV:L/AC:M/Au:N/C:N/I:N/A:C)
Published
08/22/2023
Created
08/31/2023
Added
08/31/2023
Modified
01/28/2025

Description

The libcpu component which is used by libasm of elfutils version 0.177 (git 47780c9e), suffers from denial-of-service vulnerability caused by application crashes due to out-of-bounds write (CWE-787), off-by-one error (CWE-193) and reachable assertion (CWE-617); to exploit the vulnerability, the attackers need to craft certain ELF files which bypass the missing bound checks.

Solution(s)

  • ubuntu-pro-upgrade-elfutils
  • ubuntu-pro-upgrade-libasm1
  • ubuntu-pro-upgrade-libdw1
  • ubuntu-pro-upgrade-libelf1

References

  • https://attackerkb.com/topics/cve-2020-21047
  • CVE - 2020-21047
  • USN-6322-1
  • 查看数 702
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。
注意:你的帖子需要版主批准后才能看到。

游客
回帖…