Ulrich Drepper Elfutils Integer Overflow Vulnerability
BID:13832
Info
Ulrich Drepper Elfutils Integer Overflow Vulnerability
| Bugtraq ID: | 13832 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 01 2005 12:00AM |
| Updated: | Jun 01 2005 12:00AM |
| Credit: | Discovery of this issue is credited to Tavis Ormandy and Ned Ludd of the Gentoo Linux Security Audit Team. |
| Vulnerable: |
Ulrich Drepper Elfutils 0.107 Gentoo Linux |
| Not Vulnerable: |
Ulrich Drepper Elfutils 0.108 |
Discussion
Ulrich Drepper Elfutils Integer Overflow Vulnerability
Ulrich Drepper Elfutils is prone to an integer overflow vulnerability.
This vulnerability manifests when the affected software is used to process a malicious binary. If a binary is sufficient to trigger the issue, attacker-supplied code may be executed in the context of the user that is running the vulnerable utility.
Elfutils prior to version 0.108 are affected.
Ulrich Drepper Elfutils is prone to an integer overflow vulnerability.
This vulnerability manifests when the affected software is used to process a malicious binary. If a binary is sufficient to trigger the issue, attacker-supplied code may be executed in the context of the user that is running the vulnerable utility.
Elfutils prior to version 0.108 are affected.
Exploit / POC
Ulrich Drepper Elfutils Integer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Ulrich Drepper Elfutils Integer Overflow Vulnerability
Solution:
Gentoo has released an advisory (GLSA 200506-01) and an updated eBuild to address this vulnerability. Gentoo users that are running the affected software may apply the update by issuing the following sequence of commands as a superuser:
emerge --sync
emerge --ask --oneshot --verbose ">=dev-libs/elfutils-0.108"
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Gentoo has released an advisory (GLSA 200506-01) and an updated eBuild to address this vulnerability. Gentoo users that are running the affected software may apply the update by issuing the following sequence of commands as a superuser:
emerge --sync
emerge --ask --oneshot --verbose ">=dev-libs/elfutils-0.108"
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Ulrich Drepper Elfutils Integer Overflow Vulnerability
References:
References:
- Elfutils Homepage (Ulrich Drepper)