Candidate: CVE-2019-7146 PublicDate: 2019-01-29 00:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-7146 Description: In elfutils 0.175, there is a buffer over-read in the ebl_object_note function in eblobjnote.c in libebl. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted elf file, as demonstrated by eu-readelf. Ubuntu-Description: Notes: mdeslaur> vulnerable code introduced in 0.175 Bugs: https://sourceware.org/bugzilla/show_bug.cgi?id=24075 https://sourceware.org/bugzilla/show_bug.cgi?id=24081 Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H [5.5 MEDIUM] Patches_elfutils: upstream: https://sourceware.org/git/?p=elfutils.git;a=commit;h=012018907ca05eb0ab51d424a596ef38fc87cae1 upstream: https://sourceware.org/git/?p=elfutils.git;a=commit;h=cd7ded3df43f655af945c869976401a602e46fcd upstream_elfutils: released (0.176-1) precise/esm_elfutils: not-affected (code not present) trusty_elfutils: ignored (reached end-of-life) trusty/esm_elfutils: not-affected (code not present) xenial_elfutils: not-affected (code not present) esm-infra/xenial_elfutils: not-affected (code not present) bionic_elfutils: not-affected (code not present) cosmic_elfutils: not-affected (code not present) disco_elfutils: not-affected (0.176-1) devel_elfutils: not-affected (0.176-1.1)