CVE-2019-7146

Severity CVSS v4.0:
Pending analysis
Type:
CWE-125 Out-of-bounds Read
Publication date:
29/01/2019
Last modified:
24/08/2020

Description

In elfutils 0.175, there is a buffer over-read in the ebl_object_note function in eblobjnote.c in libebl. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted elf file, as demonstrated by eu-readelf.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:elfutils_project:elfutils:0.175:*:*:*:*:*:*:*