Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Jayzhang

#45961of 53,632
5.5Total CVSS
Vulnerabilities · 1
PT-2018-2386
5.5
2018-02-09
Gnu · Gnu Binutils · CVE-2018-6872
**Name of the Vulnerable Software and Affected Versions** GNU Binutils version 2.30 **Description** The issue is related to the elf parse notes function in the elf.c file of GNU Binutils, which is associated with out-of-bounds data access errors. This can be exploited by a remote attacker using an ELF file with a NOTES segment that has a large alignment value, potentially causing a denial of service due to out-of-bounds read and segmentation violation. **Recommendations** For GNU Binutils version 2.30, consider disabling the elf parse notes function as a temporary workaround until a patch is available. Restrict access to ELF files with potentially malicious NOTES segments to minimize the risk of exploitation.