Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-45j6-5xqm-57mq

Опубликовано: 14 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 0.9
CVSS3: 4.8

Описание

A vulnerability was detected in GNU Binutils 2.47. Affected by this issue is the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component Eh Frame Section Handler. Performing a manipulation of the argument cie_length/fde_length/augmentation_data_size/write_offset results in buffer overflow. Attacking locally is a requirement. The exploit is now public and may be used. The project was informed of the problem early through a bug report but has not responded yet.

A vulnerability was detected in GNU Binutils 2.47. Affected by this issue is the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component Eh Frame Section Handler. Performing a manipulation of the argument cie_length/fde_length/augmentation_data_size/write_offset results in buffer overflow. Attacking locally is a requirement. The exploit is now public and may be used. The project was informed of the problem early through a bug report but has not responded yet.

EPSS

Процентиль: 2%
0.00117
Низкий

0.9 Low

CVSS4

4.8 Medium

CVSS3

Дефекты

CWE-119

Связанные уязвимости

CVSS3: 4.8
ubuntu
3 дня назад

A vulnerability was detected in GNU Binutils 2.47. Affected by this issue is the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component Eh Frame Section Handler. Performing a manipulation of the argument cie_length/fde_length/augmentation_data_size/write_offset results in buffer overflow. Attacking locally is a requirement. The exploit is now public and may be used. The project was informed of the problem early through a bug report but has not responded yet.

CVSS3: 4.8
redhat
3 дня назад

A flaw was found in GNU Binutils. A buffer overflow vulnerability exists in the _bfd_elf_write_section_eh_frame function, part of the Eh Frame Section Handler. A local attacker can exploit this by providing specially crafted input that manipulates arguments such as cie_length or fde_length. This manipulation can lead to a denial of service.

CVSS3: 4.8
nvd
3 дня назад

A vulnerability was detected in GNU Binutils 2.47. Affected by this issue is the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component Eh Frame Section Handler. Performing a manipulation of the argument cie_length/fde_length/augmentation_data_size/write_offset results in buffer overflow. Attacking locally is a requirement. The exploit is now public and may be used. The project was informed of the problem early through a bug report but has not responded yet.

CVSS3: 4.8
debian
3 дня назад

A vulnerability was detected in GNU Binutils 2.47. Affected by this is ...

EPSS

Процентиль: 2%
0.00117
Низкий

0.9 Low

CVSS4

4.8 Medium

CVSS3

Дефекты

CWE-119