Out-of-bounds write in elfutils - CVE-2020-21047
Published: August 31, 2023
Vulnerability identifier: #VU80175
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-21047
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error within the libcpu component. A remote attacker can create a specially crafted file, trick the victim into opening it and perform a denial of service (DoS) attack.
Affected software
elfutils
SmartFabric OS10
Ubuntu
elfutils (Ubuntu package)
libasm1 (Ubuntu package)
libdw1 (Ubuntu package)
libelf1 (Ubuntu package)
VMware Tanzu Operations Manager
Isolation Segment
VMware Tanzu Application Service for VMs
IBM CICS TX Advanced
SmartFabric OS10
Ubuntu
elfutils (Ubuntu package)
libasm1 (Ubuntu package)
libdw1 (Ubuntu package)
libelf1 (Ubuntu package)
VMware Tanzu Operations Manager
Isolation Segment
VMware Tanzu Application Service for VMs
IBM CICS TX Advanced
How to mitigate CVE-2020-21047
Install updates from vendor's website.
SmartFabric OS10 - update to 10.5.4.11
elfutils (Ubuntu package) - addressed in versions Ubuntu Pro, 0.176-1.1ubuntu0.1
libasm1 (Ubuntu package) - addressed in versions Ubuntu Pro, 0.176-1.1ubuntu0.1
libdw1 (Ubuntu package) - addressed in versions Ubuntu Pro, 0.176-1.1ubuntu0.1
libelf1 (Ubuntu package) - addressed in versions Ubuntu Pro, 0.176-1.1ubuntu0.1
VMware Tanzu Operations Manager - update to 2.10.61
Isolation Segment - addressed in versions 3.0.17, 4.0.9
VMware Tanzu Application Service for VMs - addressed in versions 3.0.17, 4.0.9
IBM CICS TX Advanced - update to 10.1.0.0 ifix24
elfutils (Ubuntu package) - addressed in versions Ubuntu Pro, 0.176-1.1ubuntu0.1
libasm1 (Ubuntu package) - addressed in versions Ubuntu Pro, 0.176-1.1ubuntu0.1
libdw1 (Ubuntu package) - addressed in versions Ubuntu Pro, 0.176-1.1ubuntu0.1
libelf1 (Ubuntu package) - addressed in versions Ubuntu Pro, 0.176-1.1ubuntu0.1
VMware Tanzu Operations Manager - update to 2.10.61
Isolation Segment - addressed in versions 3.0.17, 4.0.9
VMware Tanzu Application Service for VMs - addressed in versions 3.0.17, 4.0.9
IBM CICS TX Advanced - update to 10.1.0.0 ifix24