Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-13033

Опубликовано: 01 июл. 2018
Источник: redhat
CVSS3: 2.8

Описание

The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted ELF file, as demonstrated by _bfd_elf_parse_attributes in elf-attrs.c and bfd_malloc in libbfd.c. This can occur during execution of nm.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5binutilsNot affected
Red Hat Enterprise Linux 5binutils220Not affected
Red Hat Enterprise Linux 6binutilsWill not fix
Red Hat Enterprise Linux 8binutilsNot affected
Red Hat Enterprise Linux 8mingw-binutilsWill not fix
Red Hat Enterprise Linux 7binutilsFixedRHSA-2018:303230.10.2018

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1597436binutils: Uncontrolled Resource Consumption in execution of nm

2.8 Low

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 7 лет назад

The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted ELF file, as demonstrated by _bfd_elf_parse_attributes in elf-attrs.c and bfd_malloc in libbfd.c. This can occur during execution of nm.

CVSS3: 5.5
nvd
больше 7 лет назад

The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted ELF file, as demonstrated by _bfd_elf_parse_attributes in elf-attrs.c and bfd_malloc in libbfd.c. This can occur during execution of nm.

CVSS3: 5.5
debian
больше 7 лет назад

The Binary File Descriptor (BFD) library (aka libbfd), as distributed ...

CVSS3: 5.5
github
больше 3 лет назад

The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted ELF file, as demonstrated by _bfd_elf_parse_attributes in elf-attrs.c and bfd_malloc in libbfd.c. This can occur during execution of nm.

CVSS3: 6.5
fstec
больше 7 лет назад

Уязвимость функции _bfd_elf_parse_attributes компонента elf-attrs.c программного средства разработки GNU Binutils, позволяющая нарушителю вызвать отказ в обслуживании

2.8 Low

CVSS3