PT-2019-5659 · Gnu+1 · Gnu Binutils+1

Alan Modra

+1

·

Publicado

2019-02-19

·

Atualizado

2021-12-10

·

CVE-2019-9076

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions GNU Binutils version 2.32
Description The issue is related to the libbfd library, specifically the elf read notes function in elf.c, and is associated with unbounded resource allocation. Exploitation of this issue may allow an attacker to cause a denial of service. The problem involves an attempted excessive memory allocation.
Recommendations For GNU Binutils version 2.32, consider disabling the elf read notes function in elf.c as a temporary workaround until a patch is available. Restrict access to the libbfd library to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Allocation of Resources Without Limits

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2020-3352
ALT-PU-2020-3433
ALT-PU-2021-1230
BDU:2020-04872
CVE-2019-9076

Produtos afetados

Alt Linux
Gnu Binutils