CVE-2018-18521 log
Source |
|
Severity | Medium |
Remote | Yes |
Type | Denial of service |
Description | Divide-by-zero vulnerabilities in the function arlib_add_symbols() in arlib.c in elfutils 0.174 allow remote attackers to cause a denial of service (application crash) with a crafted ELF file, as demonstrated by eu-ranlib, because a zero sh_entsize is mishandled. |
Group | Package | Affected | Fixed | Severity | Status | Ticket |
---|---|---|---|---|---|---|
AVG-785 | elfutils | 0.174-1 | 0.175-1 | Medium | Fixed |
Date | Advisory | Group | Package | Severity | Type |
---|---|---|---|---|---|
08 Jan 2019 | ASA-201901-3 | AVG-785 | elfutils | Medium | denial of service |
References |
---|
https://sourceware.org/bugzilla/show_bug.cgi?id=23786 https://sourceware.org/ml/elfutils-devel/2018-q4/msg00055.html |