PT-2018-2454 · Gnu+4 · Gnu Binutils+4

Publicado

2018-11-20

·

Atualizado

2026-01-30

·

CVE-2018-19931

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GNU Binutils versions through 2.31
Description An issue was discovered in the Binary File Descriptor (BFD) library, which is part of GNU Binutils. The problem is a heap-based buffer overflow in the bfd elf32 swap phdr in function, located in elfcode.h, due to the lack of restriction on the number of program headers. This could potentially allow an attacker to cause a denial of service.
Recommendations For GNU Binutils versions through 2.31, consider updating to a version that fixes this issue, as the current version is affected by a heap-based buffer overflow in the bfd elf32 swap phdr in function. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-2665
ALT-PU-2019-1204
ALT-PU-2019-1367
BDU:2019-00676
CLEANSTART-2026-HF39630
CVE-2018-19931
OPENSUSE-SU-2019:2415-1
OPENSUSE-SU-2019:2432-1
OPENSUSE-SU-2019_2415-1
OPENSUSE-SU-2019_2432-1
OPENSUSE-SU-2024:10651-1
SUSE-SU-2019:2650-1
SUSE-SU-2019:2779-1
SUSE-SU-2019:2780-1
USN-4336-1
USN-4336-2

Produtos afetados

Alt Linux
Astra Linux
Gnu Binutils
Suse
Ubuntu