Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-13033

Опубликовано: 01 июл. 2018
Источник: redhat
CVSS3: 2.8
EPSS Низкий

Описание

The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted ELF file, as demonstrated by _bfd_elf_parse_attributes in elf-attrs.c and bfd_malloc in libbfd.c. This can occur during execution of nm.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5binutilsNot affected
Red Hat Enterprise Linux 5binutils220Not affected
Red Hat Enterprise Linux 6binutilsWill not fix
Red Hat Enterprise Linux 8binutilsNot affected
Red Hat Enterprise Linux 8mingw-binutilsWill not fix
Red Hat Enterprise Linux 7binutilsFixedRHSA-2018:303230.10.2018

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1597436binutils: Uncontrolled Resource Consumption in execution of nm

EPSS

Процентиль: 86%
0.03095
Низкий

2.8 Low

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 8 лет назад

The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted ELF file, as demonstrated by _bfd_elf_parse_attributes in elf-attrs.c and bfd_malloc in libbfd.c. This can occur during execution of nm.

CVSS3: 5.5
nvd
около 8 лет назад

The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted ELF file, as demonstrated by _bfd_elf_parse_attributes in elf-attrs.c and bfd_malloc in libbfd.c. This can occur during execution of nm.

CVSS3: 5.5
debian
около 8 лет назад

The Binary File Descriptor (BFD) library (aka libbfd), as distributed ...

CVSS3: 5.5
github
около 4 лет назад

The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted ELF file, as demonstrated by _bfd_elf_parse_attributes in elf-attrs.c and bfd_malloc in libbfd.c. This can occur during execution of nm.

CVSS3: 6.5
fstec
около 8 лет назад

Уязвимость функции _bfd_elf_parse_attributes компонента elf-attrs.c программного средства разработки GNU Binutils, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 86%
0.03095
Низкий

2.8 Low

CVSS3