Out-of-bounds write in elfutils - CVE-2020-21047

 

Out-of-bounds write in elfutils - CVE-2020-21047

Published: August 31, 2023


Vulnerability identifier: #VU80175
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-21047
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error within the libcpu component. A remote attacker can create a specially crafted file, trick the victim into opening it and perform a denial of service (DoS) attack.


Affected software

elfutils
SmartFabric OS10
Ubuntu
elfutils (Ubuntu package)
libasm1 (Ubuntu package)
libdw1 (Ubuntu package)
libelf1 (Ubuntu package)
VMware Tanzu Operations Manager
Isolation Segment
VMware Tanzu Application Service for VMs
IBM CICS TX Advanced

How to mitigate CVE-2020-21047

Install updates from vendor's website.

SmartFabric OS10 - update to 10.5.4.11
elfutils (Ubuntu package) - addressed in versions Ubuntu Pro, 0.176-1.1ubuntu0.1
libasm1 (Ubuntu package) - addressed in versions Ubuntu Pro, 0.176-1.1ubuntu0.1
libdw1 (Ubuntu package) - addressed in versions Ubuntu Pro, 0.176-1.1ubuntu0.1
libelf1 (Ubuntu package) - addressed in versions Ubuntu Pro, 0.176-1.1ubuntu0.1
VMware Tanzu Operations Manager - update to 2.10.61
Isolation Segment - addressed in versions 3.0.17, 4.0.9
VMware Tanzu Application Service for VMs - addressed in versions 3.0.17, 4.0.9
IBM CICS TX Advanced - update to 10.1.0.0 ifix24

External References

Related Security Bulletins