PT-2018-3973 · Gnu+5 · Gnu Binutils+5
Mingi Cho
+1
·
Published
2018-02-07
·
Updated
2024-06-15
·
CVE-2018-8945
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
GNU Binutils version 2.30
Description
The issue is related to the
bfd section from shdr function in the elf.c component of the Binary File Descriptor (BFD) library. It allows remote attackers to cause a denial of service, resulting in a segmentation fault, via a large attribute section. This is due to insufficient input validation.Recommendations
For GNU Binutils version 2.30, consider applying a patch or fix that addresses the insufficient input validation in the
bfd section from shdr function to prevent denial of service attacks. As a temporary workaround, consider restricting the size of attribute sections to prevent large sections from causing a segmentation fault.Exploit
Fix
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Centos
Gnu Binutils
Red Hat
Suse
Ubuntu