Vulnerability Name:

CVE-2018-16402 (CCN-149340)

Assigned:2018-08-15
Published:2018-08-15
Updated:2021-11-30
Summary:libelf/elf_end.c in elfutils 0.173 allows remote attackers to cause a denial of service (double free and application crash) or possibly have unspecified other impact because it tries to decompress twice.
CVSS v3 Severity:9.8 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
8.5 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
3.3 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L)
2.9 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
4.3 Medium (REDHAT CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L)
3.8 Low (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
1.7 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-415
CWE-416
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2018-16402

Source: SUSE
Type: Mailing List, Third Party Advisory
openSUSE-SU-2019:1590

Source: REDHAT
Type: Third Party Advisory
RHSA-2019:2197

Source: XF
Type: UNKNOWN
elfutils-cve201816402-dos(149340)

Source: MLIST
Type: Mailing List, Third Party Advisory
[bookkeeper-issues] 20200729 [GitHub] [bookkeeper] padma81 opened a new issue #2387: Security vulnerabilities in the apache/bookkeeper-4.9.2 image

Source: MLIST
Type: Mailing List, Third Party Advisory
[debian-lts-announce] 20211030 [SECURITY] [DLA 2802-1] elfutils security update

Source: CCN
Type: Sourceware Bugzilla – Bug 23528
When executing ./eu-nm or ./eu-readelf -aAdehIlnrsSVcp -w, AddressSanitizer catch a double-free crash.

Source: MISC
Type: Exploit, Issue Tracking, Third Party Advisory
https://sourceware.org/bugzilla/show_bug.cgi?id=23528

Source: CCN
Type: elfutils GIT Repository
libelf: Return error if elf_compress_gnu is used on SHF_COMPRESSED section.

Source: UBUNTU
Type: Third Party Advisory
USN-4012-1

Source: CCN
Type: IBM Security Bulletin 872832 (iDataPlex dx360 M4)
Multiple vulnerabilities affect Intel Manycore Platform Software Stack (Intel MPSS) for Linux and Windows

Vulnerable Configuration:Configuration 1:
  • cpe:/a:elfutils_project:elfutils:0.173:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/o:debian:debian_linux:9.0:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*

  • Configuration 4:
  • cpe:/o:opensuse:leap:15.0:*:*:*:*:*:*:*
  • OR cpe:/o:opensuse:leap:15.1:*:*:*:*:*:*:*

  • Configuration 5:
  • cpe:/o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
  • OR cpe:/o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
  • OR cpe:/o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:*

  • Configuration RedHat 1:
  • cpe:/o:redhat:enterprise_linux:7:*:*:*:*:*:*:*

  • Configuration RedHat 2:
  • cpe:/o:redhat:enterprise_linux:7::client:*:*:*:*:*

  • Configuration RedHat 3:
  • cpe:/o:redhat:enterprise_linux:7::computenode:*:*:*:*:*

  • Configuration RedHat 4:
  • cpe:/o:redhat:enterprise_linux:7::server:*:*:*:*:*

  • Configuration RedHat 5:
  • cpe:/o:redhat:enterprise_linux:7::workstation:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:201816402
    V
    CVE-2018-16402
    2023-06-22
    oval:org.opensuse.security:def:8031
    P
    libebl-plugins-0.177-150300.11.6.1 on GA media (Moderate)
    2023-06-20
    oval:org.opensuse.security:def:645
    P
    Security update for php7 (Moderate) (in QA)
    2022-10-04
    oval:org.opensuse.security:def:43656
    P
    Security update for dwarves and elfutils (Moderate)
    2022-08-01
    oval:org.opensuse.security:def:42329
    P
    Security update for dwarves and elfutils (Moderate)
    2022-08-01
    oval:org.opensuse.security:def:42425
    P
    Security update for dwarves and elfutils (Moderate)
    2022-08-01
    oval:org.opensuse.security:def:3455
    P
    coolkey-1.1.0-148.3.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3399
    P
    xalan-j2-2.7.0-264.133 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:3467
    P
    cvs-1.12.12-182.3.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:95029
    P
    libebl-plugins-0.168-4.5.3 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:50
    P
    elfutils-0.168-4.5.3 on GA media (Moderate)
    2022-06-13
    oval:org.opensuse.security:def:1329
    P
    Security update for the Linux Kernel (Live Patch 4 for SLE 15 SP3) (Important)
    2022-04-25
    oval:org.opensuse.security:def:979
    P
    Security update for xen (Important)
    2022-03-23
    oval:org.opensuse.security:def:1536
    P
    Security update for MozillaThunderbird (Important)
    2022-03-10
    oval:org.opensuse.security:def:100414
    P
    (Critical)
    2022-02-11
    oval:org.opensuse.security:def:64824
    P
    Security update for xorg-x11-server (Important)
    2021-12-14
    oval:org.opensuse.security:def:69737
    P
    Security update for MozillaFirefox (Important)
    2021-10-11
    oval:org.opensuse.security:def:71411
    P
    unixODBC-2.3.6-1.12 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:47846
    P
    pcsc-ccid-1.4.25-4.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47847
    P
    perl-32bit-5.18.2-12.17.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48189
    P
    libsaml8-2.5.5-3.3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48053
    P
    java-1_8_0-ibm-1.8.0_sr5.40-30.54.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48175
    P
    libpolkit0-0.113-5.18.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48054
    P
    java-1_8_0-openjdk-1.8.0.222-27.35.2 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47861
    P
    procmail-3.22-269.3.5 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48307
    P
    socat-1.7.2.4-3.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:48068
    P
    libQt5WebKit5-5.6.2-1.31 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:47982
    P
    cups-1.7.5-20.23.1 on GA media (Moderate)
    2021-08-16
    oval:org.opensuse.security:def:63364
    P
    python3-Twisted-19.10.0-3.2.6 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:1967
    P
    hdf5-gnu-hpc-1.10.7-2.25 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:62342
    P
    umoci-0.4.6-3.9.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:63000
    P
    cross-nvptx-gcc7-7.5.0+r278197-4.25.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:71809
    P
    elfutils-0.168-4.5.3 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:100826
    P
    elfutils-0.168-4.5.3 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62798
    P
    libmms-devel-0.6.4-1.24 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62068
    P
    elfutils-0.168-4.5.3 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62319
    P
    rsyslog-8.39.0-4.10.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:71951
    P
    librsync-devel-1.0.0-1.27 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62318
    P
    rsync-3.1.3-4.3.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:72067
    P
    skopeo-0.1.41-4.11.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:64737
    P
    Security update for bluez (Moderate)
    2021-07-22
    oval:org.opensuse.security:def:48761
    P
    ImageMagick-6.8.8.1-33.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48514
    P
    libksba8-1.3.0-23.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48399
    P
    davfs2-1.5.2-2.3 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48968
    P
    telepathy-idle-0.2.0-1.62 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48845
    P
    kernel-default-extra-4.4.73-5.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48606
    P
    python-imaging-1.1.7-21.8 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48547
    P
    libsmi-0.4.8-18.55 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48382
    P
    chrony-2.3-3.110 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48907
    P
    gnome-shell-calendar-3.20.4-77.17.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48754
    P
    pulseaudio-module-bluetooth-5.0-2.7 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:51900
    P
    Security update for gstreamer-plugins-bad (Important)
    2021-06-07
    oval:org.opensuse.security:def:68171
    P
    Security update for the Linux Kernel (Live Patch 10 for SLE 15 SP2) (Important)
    2021-04-28
    oval:org.opensuse.security:def:69632
    P
    Security update for sudo (Important)
    2021-04-20
    oval:org.opensuse.security:def:65277
    P
    Security update for MozillaFirefox (Important)
    2021-03-29
    oval:org.opensuse.security:def:68071
    P
    Security update for the Linux Kernel (Live Patch 21 for SLE 15 SP1) (Important)
    2021-02-10
    oval:org.opensuse.security:def:2174
    P
    gnuplot-5.2.2-3.3.29 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:71475
    P
    elfutils-0.168-4.5.3 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:49003
    P
    libFLAC++6-32bit-1.3.0-11.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62519
    P
    gd-2.2.5-4.6.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:107080
    P
    elfutils-0.168-4.5.3 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:116638
    P
    elfutils-0.168-4.5.3 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:49032
    P
    libqt4-sql-mysql-32bit-4.8.7-8.8.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:61734
    P
    elfutils-0.168-4.5.3 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63138
    P
    389-ds-1.4.0.3-2.39 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:71524
    P
    libHX-devel-3.22-1.26 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:49052
    P
    python3-urllib3-1.22-3.17.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:93701
    P
    elfutils-0.168-4.5.3 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:48972
    P
    NetworkManager-1.0.12-13.12.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:2748
    P
    Security update for libjpeg-turbo (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:2807
    P
    Security update for djvulibre (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:2817
    P
    Security update for webkit2gtk3 (Important)
    2020-12-02
    oval:org.opensuse.security:def:2730
    P
    Security update for avahi (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:2777
    P
    Security update for MozillaFirefox (Important)
    2020-12-02
    oval:org.opensuse.security:def:2762
    P
    Security update for audiofile (Low)
    2020-12-02
    oval:org.opensuse.security:def:2815
    P
    Security update for libjpeg-turbo (Important)
    2020-12-02
    oval:org.opensuse.security:def:2736
    P
    Security update for webkit2gtk3 (Important)
    2020-12-02
    oval:org.opensuse.security:def:2801
    P
    Security update for ImageMagick (Moderate)
    2020-12-02
    oval:org.opensuse.security:def:2726
    P
    Security update for libopenmpt (Important)
    2020-12-02
    oval:org.opensuse.security:def:2768
    P
    Security update for libvpx (Important)
    2020-12-02
    oval:org.opensuse.security:def:50562
    P
    Security update for tar (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:68714
    P
    Security update for elfutils (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50404
    P
    Security update for elfutils (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49114
    P
    gstreamer on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49262
    P
    libxerces-c-3_1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50557
    P
    Security update for webkit2gtk3 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49995
    P
    cyrus-sasl-sqlauxprop on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:72954
    P
    Security update for MozillaThunderbird (Important)
    2020-12-01
    oval:org.opensuse.security:def:65367
    P
    Security update for elfutils (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49179
    P
    libjavascriptcoregtk-4_0-18 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:73072
    P
    elfutils on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:63931
    P
    Security update for mailman (Important)
    2020-12-01
    oval:org.opensuse.security:def:66289
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:74127
    P
    Security update for python (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49740
    P
    jython on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49210
    P
    libpainter0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50611
    P
    Security update for elfutils (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50393
    P
    Security update for NetworkManager (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:74253
    P
    Security update for elfutils (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:51838
    P
    Security update for slurm (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:63691
    P
    Security update for bluez (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49074
    P
    cron on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:66381
    P
    elfutils on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50458
    P
    Security update for openldap2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49389
    P
    accountsservice on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50233
    P
    kernel-default-extra on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49243
    P
    libtasn1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50489
    P
    Security update for python3 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64033
    P
    Security update for ceph (Important)
    2020-12-01
    oval:org.opensuse.security:def:49244
    P
    libthai-data on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49838
    P
    jackson-databind on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49281
    P
    opensc on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64075
    P
    Security update for ovmf (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:49086
    P
    elfutils on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:68611
    P
    Security update for glibc (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:63825
    P
    Security update for ucode-intel (Important)
    2020-12-01
    oval:org.opensuse.security:def:50350
    P
    Security update for tiff (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64187
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:49594
    P
    pulseaudio on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:50323
    P
    Security update for clamav (Moderate)
    2020-12-01
    oval:com.redhat.rhsa:def:20192197
    P
    RHSA-2019:2197: elfutils security, bug fix, and enhancement update (Low)
    2019-08-06
    oval:org.opensuse.security:def:109877
    P
    Security update for elfutils (Moderate)
    2019-06-19
    oval:org.opensuse.security:def:90150
    P
    Security update for elfutils (Moderate)
    2019-06-13
    oval:org.opensuse.security:def:104388
    P
    Security update for elfutils (Moderate)
    2019-06-13
    oval:org.opensuse.security:def:90733
    P
    Security update for elfutils (Moderate)
    2019-06-13
    oval:org.opensuse.security:def:103805
    P
    Security update for elfutils (Moderate)
    2019-06-13
    oval:org.opensuse.security:def:97698
    P
    Security update for elfutils (Moderate)
    2019-06-13
    oval:com.ubuntu.bionic:def:201816402000
    V
    CVE-2018-16402 on Ubuntu 18.04 LTS (bionic) - low.
    2018-09-03
    oval:com.ubuntu.cosmic:def:2018164020000000
    V
    CVE-2018-16402 on Ubuntu 18.10 (cosmic) - low.
    2018-09-03
    oval:com.ubuntu.disco:def:2018164020000000
    V
    CVE-2018-16402 on Ubuntu 19.04 (disco) - low.
    2018-09-03
    oval:com.ubuntu.cosmic:def:201816402000
    V
    CVE-2018-16402 on Ubuntu 18.10 (cosmic) - low.
    2018-09-03
    oval:com.ubuntu.bionic:def:2018164020000000
    V
    CVE-2018-16402 on Ubuntu 18.04 LTS (bionic) - low.
    2018-09-03
    oval:com.ubuntu.trusty:def:201816402000
    V
    CVE-2018-16402 on Ubuntu 14.04 LTS (trusty) - low.
    2018-09-03
    oval:com.ubuntu.xenial:def:2018164020000000
    V
    CVE-2018-16402 on Ubuntu 16.04 LTS (xenial) - low.
    2018-09-03
    oval:com.ubuntu.xenial:def:201816402000
    V
    CVE-2018-16402 on Ubuntu 16.04 LTS (xenial) - low.
    2018-09-03
    BACK
    elfutils_project elfutils 0.173
    debian debian linux 9.0
    redhat enterprise linux desktop 7.0
    redhat enterprise linux server 7.0
    redhat enterprise linux workstation 7.0
    opensuse leap 15.0
    opensuse leap 15.1
    canonical ubuntu linux 16.04
    canonical ubuntu linux 18.04
    canonical ubuntu linux 18.10