CVE-2020-21047 Information
Aug 23, 2023
cve
Description
The libcpu component which is used by libasm of elfutils version 0.177 (git 47780c9e) suffers from denial-of-service vulnerability caused by application crashes due to out-of-bounds write (CWE-787) off-by-one error (CWE-193) and reachable assertion (CWE-617); to exploit the vulnerability the attackers need to craft certain ELF files which bypass the missing bound checks.
Reference
https://sourceware.org/git/?p=elfutils.git;a=commitdiff;h=99dc63b10b3878616b85df2dfd2e4e7103e414b8 https://sourceware.org/bugzilla/show_bug.cgi?id=25068
Share on: