CVE-2020-21047
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The libcpu component which is used by libasm of elfutils version 0.177 (git 47780c9e), suffers from denial-of-service vulnerability caused by application crashes due to out-of-bounds write (CWE-787), off-by-one error (CWE-193) and reachable assertion (CWE-617); to exploit the vulnerability, the attackers need to craft certain ELF files which bypass the missing bound checks.
El componente libcpu que es utilizado por libasm de elfutils versión 0.177 (git 47780c9e), sufre de una vulnerabilidad de denegación de servicio causada por caídas de la aplicación debido a una escritura fuera de límites (CWE-787), por el error off-by-one (CWE-193) y por una aserción alcanzable (CWE-617). Para explotar la vulnerabilidad, los atacantes necesitan crear ciertos archivos ELF que eludan las comprobaciones de límites faltantes.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2020-08-13 CVE Reserved
- 2023-08-22 CVE Published
- 2024-09-23 EPSS Updated
- 2024-10-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-787: Out-of-bounds Write
CAPEC
References (3)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Elfutils Project Search vendor "Elfutils Project" | Elfutils Search vendor "Elfutils Project" for product "Elfutils" | 0.177 Search vendor "Elfutils Project" for product "Elfutils" and version "0.177" | - |
Affected
|