In elfutils 0.175, a negative-sized memcpy is attempted in elf_cvt_note in libelf/note_xlate.h because of an incorrect overflow check. Crafted elf input causes a segmentation fault, leading to denial of service (program crash).
                
            References
                    | Link | Resource | 
|---|---|
| https://access.redhat.com/errata/RHSA-2019:2197 | Third Party Advisory | 
| https://access.redhat.com/errata/RHSA-2019:3575 | Third Party Advisory | 
| https://sourceware.org/bugzilla/show_bug.cgi?id=24084 | Exploit Issue Tracking Third Party Advisory | 
Configurations
                    Configuration 1 (hide)
            
            
  | 
    
Configuration 2 (hide)
            
            
  | 
    
History
                    No history.
Information
                Published : 2019-02-09 16:29
Updated : 2023-02-28 20:45
NVD link : CVE-2019-7664
Mitre link : CVE-2019-7664
CVE.ORG link : CVE-2019-7664
JSON object : View
Products Affected
                redhat
- enterprise_linux_server
 - enterprise_linux_server_aus
 - enterprise_linux_desktop
 - enterprise_linux_eus
 - enterprise_linux
 - enterprise_linux_workstation
 - enterprise_linux_server_tus
 
elfutils_project
- elfutils
 
CWE
                
                    
                        
                        CWE-787
                        
            Out-of-bounds Write
