Wind River Support Network

HomeDefectsLIN7-2698
Fixed

LIN7-2698 : Security Advisory - elfutils - CVE-2014-9447

Created: Jan 14, 2015    Updated: Sep 8, 2018
Resolved Date: Apr 21, 2015
Found In Version: 7.0
Fix Version: 7.0.0.5
Severity: Standard
Applicable for: Wind River Linux 7
Component/s: Userspace

Description

Directory traversal vulnerability in the read_long_names function in libelf/elf_begin.c in elfutils 0.152 and 0.161 allows remote attackers to write to arbitrary files to the root directory via a / (slash) in a crafted archive, as demonstrated using the ar program.

http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-9447

Other Downloads


CVEs


Live chat
Online