Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c64w-hpm6-xx8w

Опубликовано: 22 апр. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious file, which could lead to arbitrary code execution, allowing the attacker to run unauthorized commands, or cause a denial of service, making the system unavailable.

A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious file, which could lead to arbitrary code execution, allowing the attacker to run unauthorized commands, or cause a denial of service, making the system unavailable.

EPSS

Процентиль: 7%
0.00171
Низкий

7.8 High

CVSS3

Дефекты

CWE-122

Связанные уязвимости

CVSS3: 7.8
ubuntu
3 месяца назад

A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious file, which could lead to arbitrary code execution, allowing the attacker to run unauthorized commands, or cause a denial of service, making the system unavailable.

CVSS3: 7.8
redhat
4 месяца назад

A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious file, which could lead to arbitrary code execution, allowing the attacker to run unauthorized commands, or cause a denial of service, making the system unavailable.

CVSS3: 7.8
nvd
3 месяца назад

A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious file, which could lead to arbitrary code execution, allowing the attacker to run unauthorized commands, or cause a denial of service, making the system unavailable.

CVSS3: 7.8
msrc
3 месяца назад

Binutils: binutils: arbitrary code execution via malformed xcoff object file processing

CVSS3: 7.8
debian
3 месяца назад

A flaw was found in binutils. A heap-buffer-overflow vulnerability exi ...

EPSS

Процентиль: 7%
0.00171
Низкий

7.8 High

CVSS3

Дефекты

CWE-122