PT-2018-3973 · Gnu+5 · Gnu Binutils+5

Mingi Cho

+1

·

Published

2018-02-07

·

Updated

2024-06-15

·

CVE-2018-8945

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions GNU Binutils version 2.30
Description The issue is related to the bfd section from shdr function in the elf.c component of the Binary File Descriptor (BFD) library. It allows remote attackers to cause a denial of service, resulting in a segmentation fault, via a large attribute section. This is due to insufficient input validation.
Recommendations For GNU Binutils version 2.30, consider applying a patch or fix that addresses the insufficient input validation in the bfd section from shdr function to prevent denial of service attacks. As a temporary workaround, consider restricting the size of attribute sections to prevent large sections from causing a segmentation fault.

Exploit

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1204
ALT-PU-2019-1367
BDU:2023-07803
CESA-2018_3032
CVE-2018-8945
MGASA-2019-0169
OPENSUSE-SU-2018_3223-1
OPENSUSE-SU-2018_3323-1
OPENSUSE-SU-2019:2415-1
OPENSUSE-SU-2019:2432-1
OPENSUSE-SU-2019_2415-1
OPENSUSE-SU-2019_2432-1
OPENSUSE-SU-2024:10651-1
RHSA-2018:3032
RHSA-2018_3032
SUSE-SU-2018:3170-1
SUSE-SU-2018:3207-1
SUSE-SU-2018:3207-2
SUSE-SU-2019:2779-1
SUSE-SU-2019:2780-1
USN-4336-1
USN-4336-2

Affected Products

Alt Linux
Centos
Gnu Binutils
Red Hat
Suse
Ubuntu