PT-2019-5659 · Gnu+1 · Gnu Binutils+1

Alan Modra

+1

·

Published

2019-02-19

·

Updated

2021-12-10

·

CVE-2019-9076

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions GNU Binutils version 2.32
Description The issue is related to the libbfd library, specifically the elf read notes function in elf.c, and is associated with unbounded resource allocation. Exploitation of this issue may allow an attacker to cause a denial of service. The problem involves an attempted excessive memory allocation.
Recommendations For GNU Binutils version 2.32, consider disabling the elf read notes function in elf.c as a temporary workaround until a patch is available. Restrict access to the libbfd library to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3352
ALT-PU-2020-3433
ALT-PU-2021-1230
BDU:2020-04872
CVE-2019-9076

Affected Products

Alt Linux
Gnu Binutils