PT-2018-3956 · Gnu+4 · Gnu Binutils+4

Rookie

·

Published

2018-07-01

·

Updated

2021-07-21

·

CVE-2018-13033

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions GNU Binutils version 2.30
Description The issue is related to the bfd elf parse attributes function in the elf-attrs.c component of GNU Binutils, which is associated with unlimited memory allocation. This can be exploited by a remote attacker using a specially crafted ELF file, leading to a denial of service (excessive memory allocation and application crash). The vulnerability can be triggered during the execution of nm, for example, via the bfd elf parse attributes function in elf-attrs.c and the bfd malloc function in libbfd.c.
Recommendations For GNU Binutils version 2.30, consider disabling the bfd elf parse attributes function as a temporary workaround until a patch is available. Restrict access to the elf-attrs.c component to minimize the risk of exploitation. Avoid using specially crafted ELF files that could trigger the excessive memory allocation issue.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1204
ALT-PU-2019-1367
BDU:2023-07784
CESA-2018_3032
CVE-2018-13033
RHSA-2018:3032
RHSA-2018_3032
USN-4336-1
USN-4336-2

Affected Products

Alt Linux
Centos
Gnu Binutils
Red Hat
Ubuntu