Elfutils libdw 'check_section()' Function Remote Heap Based Buffer Overflow Vulnerability
BID:66714
Info
Elfutils libdw 'check_section()' Function Remote Heap Based Buffer Overflow Vulnerability
| Bugtraq ID: | 66714 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-0172 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 09 2014 12:00AM |
| Updated: | Apr 13 2015 10:05PM |
| Credit: | Florian Weimer of the Red Hat Product Security Team. |
| Vulnerable: |
Ubuntu Ubuntu Linux 14.04 LTS Ubuntu Ubuntu Linux 13.10 Ubuntu Ubuntu Linux 12.10 i386 Ubuntu Ubuntu Linux 12.10 amd64 Ubuntu Ubuntu Linux 12.10 Redhat elfutils 0.153 |
| Not Vulnerable: | |
Discussion
Elfutils libdw 'check_section()' Function Remote Heap Based Buffer Overflow Vulnerability
Elfutils libdw is prone to a remote heap-based buffer-overflow vulnerability because it fails to properly sanitize user-supplied input.
Successful exploits allow remote attackers to execute arbitrary code in the context of the vulnerable application. Failed exploit attempts likely result in denial-of-service conditions.
Elfutils 0.153 and later are vulnerable.
Elfutils libdw is prone to a remote heap-based buffer-overflow vulnerability because it fails to properly sanitize user-supplied input.
Successful exploits allow remote attackers to execute arbitrary code in the context of the vulnerable application. Failed exploit attempts likely result in denial-of-service conditions.
Elfutils 0.153 and later are vulnerable.
Exploit / POC
Elfutils libdw 'check_section()' Function Remote Heap Based Buffer Overflow Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Elfutils libdw 'check_section()' Function Remote Heap Based Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Elfutils libdw 'check_section()' Function Remote Heap Based Buffer Overflow Vulnerability
References:
References:
- CVE-2014-0172 Check for overflow before calling malloc to uncompress data. (Mark Wielaard)
- Elfutils Homepage (Debian)
- CVE-2014-0172 elfutils: integer overflow, leading to a heap-based buffer overflo (Red Hat Bugzilla)
- USN-2188-1: elfutils vulnerability (Ubuntu)