PoC Index

CVE-2018-18521

MEDIUM 5.5EPSS 1.8%

Divide-by-zero vulnerabilities in the function arlib_add_symbols() in arlib.c in elfutils 0.174 allow remote attackers to cause a denial of service (application crash) with a crafted ELF file, as demonstrated by eu-ranlib, because a zero sh_entsize is mishandled.

CVSS v3.1
5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS v2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
EPSS
1.82% chance of exploitation in the next 30 days, 77th percentile
Published
2018-10-19
Updated
2024-08-05

Proof-of-concept exploits (1)

References

Related