发布时间: 2025年2月17日
修改时间: 2025年2月21日
A vulnerability has been found in GNU elfutils 0.192 and classified as problematic. This vulnerability affects the function handle_dynamic_symtab of the file readelf.c of the component eu-read. The manipulation leads to null pointer dereference. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The patch is identified as b38e562a4c907e08171c76b8b2def8464d5a104a. It is recommended to apply a patch to fix this issue.
NVD | openEuler | |
---|---|---|
CVSS评分 | 4.8 | 3.3 |
Attack Vector | Local | Local |
Attack Complexity | Low | Low |
Privileges Required | Low | Low |
User Interaction | None | None |
Scope | Unchanged | |
Confidentiality | None | |
Integrity | None | |
Availability | Low |
公告名 | 概要 | 发布时间 |
---|---|---|
KylinSec-SA-2025-1266 | elfutils security update | 2025年2月21日 |
产品 | 包 | 状态 |
---|---|---|
KY3.4-5A | elfutils | Unaffected |
KY3.5.2 | elfutils | Unaffected |
V6 | elfutils | Fixed |