Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p2w9-g2w7-8fw9

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.1

Описание

An out of bounds flaw was found in GNU binutils objdump utility version 2.36. An attacker could use this flaw and pass a large section to avr_elf32_load_records_from_section() probably resulting in a crash or in some cases memory corruption. The highest threat from this vulnerability is to integrity as well as system availability.

An out of bounds flaw was found in GNU binutils objdump utility version 2.36. An attacker could use this flaw and pass a large section to avr_elf32_load_records_from_section() probably resulting in a crash or in some cases memory corruption. The highest threat from this vulnerability is to integrity as well as system availability.

EPSS

Процентиль: 41%
0.00193
Низкий

7.1 High

CVSS3

Дефекты

CWE-119
CWE-787

Связанные уязвимости

CVSS3: 7.1
ubuntu
больше 4 лет назад

An out of bounds flaw was found in GNU binutils objdump utility version 2.36. An attacker could use this flaw and pass a large section to avr_elf32_load_records_from_section() probably resulting in a crash or in some cases memory corruption. The highest threat from this vulnerability is to integrity as well as system availability.

CVSS3: 6.1
redhat
около 5 лет назад

An out of bounds flaw was found in GNU binutils objdump utility version 2.36. An attacker could use this flaw and pass a large section to avr_elf32_load_records_from_section() probably resulting in a crash or in some cases memory corruption. The highest threat from this vulnerability is to integrity as well as system availability.

CVSS3: 7.1
nvd
больше 4 лет назад

An out of bounds flaw was found in GNU binutils objdump utility version 2.36. An attacker could use this flaw and pass a large section to avr_elf32_load_records_from_section() probably resulting in a crash or in some cases memory corruption. The highest threat from this vulnerability is to integrity as well as system availability.

CVSS3: 7.1
debian
больше 4 лет назад

An out of bounds flaw was found in GNU binutils objdump utility versio ...

CVSS3: 7.1
fstec
больше 4 лет назад

Уязвимость функции avr_elf32_load_records_from_section() программного средства разработки GNU Binutils, связанная с записью за границами буфера в памяти, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 41%
0.00193
Низкий

7.1 High

CVSS3

Дефекты

CWE-119
CWE-787