UBUNTU-CVE-2020-21047
Dashboard / Vulnerabilities / UBUNTU-CVE-2020-21047
UBUNTU-CVE-2020-21047
Summary:
Details: The libcpu component which is used by libasm of elfutils version 0.177 (git 47780c9e), suffers from denial-of-service vulnerability caused by application crashes due to out-of-bounds write (CWE-787), off-by-one error (CWE-193) and reachable assertion (CWE-617); to exploit the vulnerability, the attackers need to craft certain ELF files which bypass the missing bound checks.
References: https://ubuntu.com/security/CVE-2020-21047, https://sourceware.org/git/?p=elfutils.git;a=commitdiff;h=99dc63b10b3878616b85df2dfd2e4e7103e414b8, https://sourceware.org/bugzilla/show_bug.cgi?id=25068, https://ubuntu.com/security/notices/USN-6322-1, https://www.cve.org/CVERecord?id=CVE-2020-21047
Affected packages
Package
Name: elfutils
Purl: pkg:deb/ubuntu/[email protected]+esm1?arch=source&distro=trusty/esm
Affected ranges
Type: ECOSYSTEM
Events:
