~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to active/CVE-2017-7607

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
PublicDateAtUSN: 2017-04-09
2
 
Candidate: CVE-2017-7607
3
 
PublicDate: 2017-04-09
4
 
References:
5
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7607
6
 
 https://blogs.gentoo.org/ago/2017/04/03/elfutils-heap-based-buffer-overflow-in-handle_gnu_hash-readelf-c/
7
 
 https://usn.ubuntu.com/usn/usn-3670-1
8
 
Description:
9
 
 The handle_gnu_hash function in readelf.c in elfutils 0.168 allows remote
10
 
 attackers to cause a denial of service (heap-based buffer over-read and
11
 
 application crash) via a crafted ELF file.
12
 
Ubuntu-Description:
13
 
Notes:
14
 
Bugs:
15
 
 https://sourceware.org/bugzilla/show_bug.cgi?id=21299
16
 
 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=859996
17
 
Priority: medium
18
 
Discovered-by: Agostino Sarubbo
19
 
Assigned-to: mdeslaur
20
 
 
21
 
Patches_elfutils:
22
 
 upstream: https://sourceware.org/git/?p=elfutils.git;a=commitdiff;h=9d84fdd78705d7a1b9947a9f4ca77fbccdd76d4a
23
 
upstream_elfutils: needed
24
 
precise_elfutils: ignored (reached end-of-life)
25
 
precise/esm_elfutils: needed
26
 
trusty_elfutils: released (0.158-0ubuntu5.3)
27
 
vivid/stable-phone-overlay_elfutils: ignored (reached end-of-life)
28
 
vivid/ubuntu-core_elfutils: DNE
29
 
xenial_elfutils: released (0.165-3ubuntu1.1)
30
 
yakkety_elfutils: ignored (reached end-of-life)
31
 
zesty_elfutils: ignored (reached end-of-life)
32
 
artful_elfutils: released (0.170-0.1)
33
 
bionic_elfutils: released (0.170-0.4)
34
 
devel_elfutils: released (0.170-0.4)