PT-2019-6399 · Gnu+3 · Gnu Binutils+3

Published

2019-02-19

·

Updated

2021-12-10

·

CVE-2019-9073

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions GNU Binutils version 2.32
Description The issue is related to the bfd elf slurp version tables function in the elf.c component of the GNU Binutils, which is associated with unlimited memory allocation. This allows a remote attacker to cause a denial of service. The problem is an attempted excessive memory allocation.
Recommendations For GNU Binutils version 2.32, consider updating to a newer version to mitigate the risk, as the current version has an issue with excessive memory allocation in the bfd elf slurp version tables function. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3352
ALT-PU-2020-3433
ALT-PU-2021-1230
BDU:2023-07811
CVE-2019-9073
MGASA-2019-0169
USN-4336-1
USN-4336-2

Affected Products

Alt Linux
Astra Linux
Gnu Binutils
Ubuntu