PT-2018-3959 · Gnu+4 · Gnu Binutils+4

Rookie

·

Published

2018-09-19

·

Updated

2024-06-15

·

CVE-2018-17360

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions GNU Binutils version 2.31
Description An issue in the Binary File Descriptor (BFD) library allows an attacker to cause a denial of service through a crafted PE file. This can be triggered by the executable objdump. The vulnerability is related to a heap-based buffer over-read in the bfd getl32 function in libbfd.c. It enables a remote attacker to disrupt service using a specially crafted file.
Recommendations For GNU Binutils version 2.31, consider updating to a newer version to mitigate the risk, as the current version contains a heap-based buffer over-read vulnerability in the bfd getl32 function. As a temporary workaround, consider restricting the use of the objdump executable until a patch is available.

Exploit

Fix

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-3046
BDU:2023-07788
CVE-2018-17360
OPENSUSE-SU-2019:2415-1
OPENSUSE-SU-2019:2432-1
OPENSUSE-SU-2019_2415-1
OPENSUSE-SU-2019_2432-1
OPENSUSE-SU-2024:10651-1
SUSE-SU-2019:2650-1
SUSE-SU-2019:2779-1
SUSE-SU-2019:2780-1
USN-4336-1
USN-4336-2

Affected Products

Alt Linux
Astra Linux
Gnu Binutils
Suse
Ubuntu