Vulnerabilities (CVE)

Filtered by vendor Elfutils Project Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2014-0172 1 Elfutils Project 1 Elfutils 2017-07-01 6.8 MEDIUM N/A
Integer overflow in the check_section function in dwarf_begin_elf.c in the libdw library, as used in elfutils 0.153 and possibly through 0.158 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a malformed compressed debug section in an ELF file, which triggers a heap-based buffer overflow.
CVE-2014-9447 1 Elfutils Project 1 Elfutils 2015-04-18 6.4 MEDIUM N/A
Directory traversal vulnerability in the read_long_names function in libelf/elf_begin.c in elfutils 0.152 and 0.161 allows remote attackers to write to arbitrary files to the root directory via a / (slash) in a crafted archive, as demonstrated using the ar program.