PT-2018-2625 · Gnu+4 · Gnu Binutils+4

Publicado

2018-11-27

·

Atualizado

2024-06-15

·

CVE-2018-20671

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions GNU Binutils versions through 2.31.1
Description The issue is related to an integer overflow vulnerability in the load specific debug section function in objdump.c, which can trigger a heap-based buffer overflow via a crafted section size. This vulnerability may allow an attacker to cause a denial of service.
Recommendations For GNU Binutils versions through 2.31.1, update to a version that contains a fix for this issue to prevent potential exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Integer Overflow

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2019-1204
ALT-PU-2019-1367
ALT-PU-2019-3046
BDU:2019-01241
CVE-2018-20671
OPENSUSE-SU-2019:2415-1
OPENSUSE-SU-2019:2432-1
OPENSUSE-SU-2019_2415-1
OPENSUSE-SU-2019_2432-1
OPENSUSE-SU-2024:10651-1
SUSE-SU-2019:2650-1
SUSE-SU-2019:2779-1
SUSE-SU-2019:2780-1
USN-4336-1
USN-4336-2
USN-6413-1

Produtos afetados

Alt Linux
Astra Linux
Gnu Binutils
Suse
Ubuntu