Red Hat Bugzilla – Bug 1625055
CVE-2018-16403 elfutils: Heap-based buffer over-read in libdw/dwarf_getabbrev.c and libwd/dwarf_hasattr.c causes crash
Last modified: 2018-10-24 08:36:39 EDT
Elfutils through version 0.173 is vulnerable to a heap-based buffer over-read due to incorrect checks for the end of attribute lists in the libdw/dwarf_getabbrev.c:__libdw_getabbrev() and libdw/dwarf_hasattr.c:dwarf_hasattr() functions. An attacker could exploit this to cause a crash via a crafted ELF. Upstream Bug: https://sourceware.org/bugzilla/show_bug.cgi?id=23529 Upstream Patch: https://sourceware.org/git/?p=elfutils.git;a=patch;h=6983e59b727458a6c64d9659c85f08218bc4fcda
Created elfutils tracking bugs for this issue: Affects: fedora-all [bug 1625056]