CVE-2020-21047
22.08.2023, 19:16
The libcpu component which is used by libasm of elfutils version 0.177 (git 47780c9e), suffers from denial-of-service vulnerability caused by application crashes due to out-of-bounds write (CWE-787), off-by-one error (CWE-193) and reachable assertion (CWE-617); to exploit the vulnerability, the attackers need to craft certain ELF files which bypass the missing bound checks.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| elfutils_project | elfutils | 0.177 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Amazon Linux Releases
Amazon Package | |||
|---|---|---|---|
| elfutils |
| ||
| elfutils-debuginfo |
| ||
| elfutils-default-yama-scope |
| ||
| elfutils-devel |
| ||
| elfutils-devel-static |
| ||
| elfutils-libelf |
| ||
| elfutils-libelf-devel |
| ||
| elfutils-libelf-devel-static |
| ||
| elfutils-libs |
|
Common Weakness Enumeration
References