PT-2018-3957 · Gnu+4 · Gnu Binutils+4
Rookie
·
Published
2018-09-19
·
Updated
2024-06-15
·
CVE-2018-17358
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
GNU Binutils version 2.31
Description
The issue is related to an invalid memory access in the
bfd stab section find nearest line function of the syms.c component in the GNU Binutils. This can be exploited by an attacker to cause a denial of service, resulting in an application crash, by using a specially crafted ELF file. The vulnerability is associated with a buffer overflow in memory.Recommendations
For GNU Binutils version 2.31, consider updating to a newer version to mitigate the risk of exploitation. As a temporary workaround, restrict the use of specially crafted ELF files to minimize the risk of causing a denial of service.
Exploit
Fix
DoS
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Gnu Binutils
Suse
Ubuntu