CVE-2022-21711
Summary
| CVE | CVE-2022-21711 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-01-24 20:15:00 UTC |
| Updated | 2023-02-16 17:07:00 UTC |
| Description | elfspirit is an ELF static analysis and injection framework that parses, manipulates, and camouflages ELF files. When analyzing the ELF file format in versions prior to 1.1, there is an out-of-bounds read bug, which can lead to application crashes or information leakage. By constructing a special format ELF file, the information of any address can be leaked. elfspirit version 1.1 contains a patch for this issue. |
Risk And Classification
Problem Types: CWE-125
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Elfspirit Project | Elfspirit | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Fix #1 about out-of-bounds · liyansong2018/elfspirit@c5b0f5a · GitHub | MISC | github.com | |
| Out-of-bounds read in elf parsing. · Issue #1 · liyansong2018/elfspirit · GitHub | MISC | github.com | |
| Out-of-bounds Read in parsing component. · Advisory · liyansong2018/elfspirit · GitHub | CONFIRM | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.