USN-6322-1
Dashboard / Vulnerabilities / USN-6322-1
USN-6322-1
Summary: elfutils vulnerabilities
Details: It was discovered that elfutils incorrectly handled certain malformed files. If a user or automated system were tricked into processing a specially crafted file, elfutils could be made to crash or consume resources, resulting in a denial of service. This issue only affected Ubuntu 14.04 LTS. (CVE-2018-16062, CVE-2018-16403, CVE-2018-18310, CVE-2018-18520, CVE-2018-18521, CVE-2019-7149, CVE-2019-7150, CVE-2019-7665) It was discovered that elfutils incorrectly handled bounds checks in certain functions when processing malformed files. If a user or automated system were tricked into processing a specially crafted file, elfutils could be made to crash or consume resources, resulting in a denial of service. (CVE-2020-21047, CVE-2021-33294)
References: https://ubuntu.com/security/notices/USN-6322-1, https://ubuntu.com/security/CVE-2018-16062, https://ubuntu.com/security/CVE-2018-16403, https://ubuntu.com/security/CVE-2018-18310, https://ubuntu.com/security/CVE-2018-18520, https://ubuntu.com/security/CVE-2018-18521, https://ubuntu.com/security/CVE-2019-7149, https://ubuntu.com/security/CVE-2019-7150, https://ubuntu.com/security/CVE-2019-7665, https://ubuntu.com/security/CVE-2020-21047, https://ubuntu.com/security/CVE-2021-33294
Affected packages
Package
Name: elfutils
Purl: pkg:deb/ubuntu/elfutils?arch=source&distro=trusty%2Fesm
Affected ranges
Type: ECOSYSTEM
Events:
