#VU15371 Segmentation fault in elfutils - CVE-2018-18310
Published: October 15, 2018 / Updated: October 16, 2018
elfutils
Sourceware
Description
The vulnerability allows a local attacker to cause DoS condition on the target system.
The vulnerability exists in the dwfl_segment_report_module.c source code file in the libdwfl library due to improper handling of Executable and Linkable Format (ELF) files. A local attacker can send an ELF file that submits malicious input, execute the eu-stack command, trigger a segmentation fault and cause the affected application to crash.