PT-2019-6394 · Gnu+4 · Gnu Binutils+4
Ren Kimura
·
Published
2019-06-18
·
Updated
2024-06-15
·
CVE-2019-14250
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
GNU Binutils version 2.32
Description
The issue is related to an integer overflow in the simple object elf match function of the libiberty component in simple-object-elf.c. This can lead to a heap-based buffer overflow. The exploitation of this issue allows a remote attacker to cause a denial of service.
Recommendations
For GNU Binutils version 2.32, consider updating to a newer version that contains a fix for this issue, as the current version is affected by an integer overflow in the
simple object elf match function.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Integer Overflow
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Gnu Binutils
Suse
Ubuntu