In elfutils 0.175, a negative-sized memcpy is attempted in elf_cvt_note in libelf/note_xlate.h because of an incorrect overflow check. Crafted elf input causes a segmentation fault, leading to denial of service (program crash).
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://sourceware.org/bugzilla/show_bug.cgi?id=24084 | issue tracking exploit third party advisory |
https://access.redhat.com/errata/RHSA-2019:2197 | third party advisory vendor advisory |
https://access.redhat.com/errata/RHSA-2019:3575 | third party advisory vendor advisory |