CVE-2014-0172

Integer overflow in the check_section function in dwarf_begin_elf.c in the libdw library, as used in elfutils 0.153 and possibly through 0.158 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a malformed compressed debug section in an ELF file, which triggers a heap-based buffer overflow.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 83%
Affected Products (NVD)
VendorProductVersion
elfutils_projectelfutils
0.153
elfutils_projectelfutils
0.154
elfutils_projectelfutils
0.155
elfutils_projectelfutils
0.156
elfutils_projectelfutils
0.157
elfutils_projectelfutils
0.158
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
elfutils
bookworm
0.188-2.1
fixed
bullseye
0.183-1
fixed
sid
0.192-4
fixed
squeeze
not-affected
trixie
0.192-4
fixed
wheezy
not-affected
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
elfutils
lucid
not-affected
precise
not-affected
quantal
Fixed 0.153-1ubuntu1.1
released
saucy
Fixed 0.157-1ubuntu1.1
released
trusty
Fixed 0.158-0ubuntu5.1
released
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
elfutils
suse enterprise sap 12 SP5
0.158-7.7.2
fixed
suse enterprise server 12 SP1
0.158-6.1
fixed
suse enterprise server 12 SP2
0.158-6.1
fixed
suse enterprise server 12 SP3
0.158-6.1
fixed
suse enterprise server 12 SP5
0.158-7.7.2
fixed
libasm1
suse enterprise sap 12 SP5
0.158-7.7.2
fixed
suse enterprise server 12 SP1
0.158-6.1
fixed
suse enterprise server 12 SP2
0.158-6.1
fixed
suse enterprise server 12 SP3
0.158-6.1
fixed
suse enterprise server 12 SP5
0.158-7.7.2
fixed
libasm1-32bit
suse enterprise sap 12 SP5
0.158-7.7.2
fixed
suse enterprise server 12 SP1
0.158-6.1
fixed
suse enterprise server 12 SP2
0.158-6.1
fixed
suse enterprise server 12 SP3
0.158-6.1
fixed
suse enterprise server 12 SP5
0.158-7.7.2
fixed
libdw1
suse enterprise sap 12 SP5
0.158-7.7.2
fixed
suse enterprise server 12 SP1
0.158-6.1
fixed
suse enterprise server 12 SP2
0.158-6.1
fixed
suse enterprise server 12 SP3
0.158-6.1
fixed
suse enterprise server 12 SP5
0.158-7.7.2
fixed
libdw1-32bit
suse enterprise sap 12 SP5
0.158-7.7.2
fixed
suse enterprise server 12 SP1
0.158-6.1
fixed
suse enterprise server 12 SP2
0.158-6.1
fixed
suse enterprise server 12 SP3
0.158-6.1
fixed
suse enterprise server 12 SP5
0.158-7.7.2
fixed
libebl1
suse enterprise sap 12 SP5
0.158-7.7.2
fixed
suse enterprise server 12 SP1
0.158-6.1
fixed
suse enterprise server 12 SP2
0.158-6.1
fixed
suse enterprise server 12 SP3
0.158-6.1
fixed
suse enterprise server 12 SP5
0.158-7.7.2
fixed
libebl1-32bit
suse enterprise sap 12 SP5
0.158-7.7.2
fixed
suse enterprise server 12 SP1
0.158-6.1
fixed
suse enterprise server 12 SP2
0.158-6.1
fixed
suse enterprise server 12 SP3
0.158-6.1
fixed
suse enterprise server 12 SP5
0.158-7.7.2
fixed
libelf-devel
suse enterprise sap 12 SP5
0.158-7.7.2
fixed
suse enterprise server 12 SP5
0.158-7.7.2
fixed
libelf1
suse enterprise sap 12 SP5
0.158-7.7.2
fixed
suse enterprise server 12 SP1
0.158-6.1
fixed
suse enterprise server 12 SP2
0.158-6.1
fixed
suse enterprise server 12 SP3
0.158-6.1
fixed
suse enterprise server 12 SP5
0.158-7.7.2
fixed
libelf1-32bit
suse enterprise sap 12 SP5
0.158-7.7.2
fixed
suse enterprise server 12 SP1
0.158-6.1
fixed
suse enterprise server 12 SP2
0.158-6.1
fixed
suse enterprise server 12 SP3
0.158-6.1
fixed
suse enterprise server 12 SP5
0.158-7.7.2
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
elfutils
RHEL 7
0:0.160-1.el7
fixed
elfutils-devel
RHEL 7
0:0.160-1.el7
fixed
elfutils-devel-static
RHEL 7
0:0.160-1.el7
fixed
elfutils-libelf
RHEL 7
0:0.160-1.el7
fixed
elfutils-libelf-devel
RHEL 7
0:0.160-1.el7
fixed
elfutils-libelf-devel-static
RHEL 7
0:0.160-1.el7
fixed
elfutils-libs
RHEL 7
0:0.160-1.el7
fixed
Common Weakness Enumeration