Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w5g7-j55x-m535

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

A flaw exists in binutils in bfd/pef.c. An attacker who is able to submit a crafted PEF file to be parsed by objdump could cause a heap buffer overflow -> out-of-bounds read that could lead to an impact to application availability. This flaw affects binutils versions prior to 2.34.

A flaw exists in binutils in bfd/pef.c. An attacker who is able to submit a crafted PEF file to be parsed by objdump could cause a heap buffer overflow -> out-of-bounds read that could lead to an impact to application availability. This flaw affects binutils versions prior to 2.34.

EPSS

Процентиль: 45%
0.00227
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-125
CWE-20

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 5 лет назад

A flaw exists in binutils in bfd/pef.c. An attacker who is able to submit a crafted PEF file to be parsed by objdump could cause a heap buffer overflow -> out-of-bounds read that could lead to an impact to application availability. This flaw affects binutils versions prior to 2.34.

CVSS3: 5.5
redhat
около 6 лет назад

A flaw exists in binutils in bfd/pef.c. An attacker who is able to submit a crafted PEF file to be parsed by objdump could cause a heap buffer overflow -> out-of-bounds read that could lead to an impact to application availability. This flaw affects binutils versions prior to 2.34.

CVSS3: 5.5
nvd
около 5 лет назад

A flaw exists in binutils in bfd/pef.c. An attacker who is able to submit a crafted PEF file to be parsed by objdump could cause a heap buffer overflow -> out-of-bounds read that could lead to an impact to application availability. This flaw affects binutils versions prior to 2.34.

CVSS3: 5.5
msrc
около 5 лет назад

A flaw exists in binutils in bfd/pef.c. An attacker who is able to submit a crafted PEF file to be parsed by objdump could cause a heap buffer overflow -> out-of-bounds read that could lead to an impact to application availability. This flaw affects binutils versions prior to 2.34.

CVSS3: 5.5
debian
около 5 лет назад

A flaw exists in binutils in bfd/pef.c. An attacker who is able to sub ...

EPSS

Процентиль: 45%
0.00227
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-125
CWE-20