PT-2018-2388 · Gnu+5 · Gnu Binutils+5
Skysider
·
Published
2018-02-28
·
Updated
2024-06-15
·
CVE-2018-7569
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
GNU Binutils version 2.30
Description
The issue is related to the
parse die function in the dwarf2.c file of the Binary File Descriptor (BFD) library, also known as libbfd, which is part of GNU Binutils. It allows remote attackers to cause a denial of service, resulting in an integer underflow or overflow and an application crash, by using an ELF file with a corrupt DWARF FORM block.Recommendations
For GNU Binutils version 2.30, consider updating to a newer version that contains a fix for this issue, as the current version is affected by the integer underflow or overflow vulnerability in the
dwarf2.c file. As a temporary workaround, consider restricting the use of the parse die function in the dwarf2.c file until a patch is available.Exploit
Fix
DoS
Integer Underflow
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Centos
Gnu Binutils
Red Hat
Suse
Ubuntu