CVE-2017-7609 PUBLISHED

elf_compress.c in elfutils 0.168 does not validate the zlib compression factor, which allows remote attackers to cause a denial of service (memory consumption) via a crafted ELF file.

EPSS 0.48% · 64.7th percentile

Risk Scores

EPSS Score
0.48%
64.7th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSelfutils0, 0.163-4ubuntu1, 0.163-5.1
Ubuntu:18.04:LTSelfutils0, 0.170-0.1, 0.170-0.2

Timeline

References

Open in Interactive Console →