PT-2018-3956 · Gnu+4 · Gnu Binutils+4

Rookie

·

Publicado

2018-07-01

·

Atualizado

2021-07-21

·

CVE-2018-13033

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions GNU Binutils version 2.30
Description The issue is related to the bfd elf parse attributes function in the elf-attrs.c component of GNU Binutils, which is associated with unlimited memory allocation. This can be exploited by a remote attacker using a specially crafted ELF file, leading to a denial of service (excessive memory allocation and application crash). The vulnerability can be triggered during the execution of nm, for example, via the bfd elf parse attributes function in elf-attrs.c and the bfd malloc function in libbfd.c.
Recommendations For GNU Binutils version 2.30, consider disabling the bfd elf parse attributes function as a temporary workaround until a patch is available. Restrict access to the elf-attrs.c component to minimize the risk of exploitation. Avoid using specially crafted ELF files that could trigger the excessive memory allocation issue.

Exploit

Correção

DoS

Allocation of Resources Without Limits

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2019-1204
ALT-PU-2019-1367
BDU:2023-07784
CESA-2018_3032
CVE-2018-13033
RHSA-2018:3032
RHSA-2018_3032
USN-4336-1
USN-4336-2

Produtos afetados

Alt Linux
Centos
Gnu Binutils
Red Hat
Ubuntu