Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-19932

Опубликовано: 30 нояб. 2018
Источник: redhat
CVSS3: 3.3
EPSS Низкий

Описание

An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils through 2.31. There is an integer overflow and infinite loop caused by the IS_CONTAINED_BY_LMA macro in elf.c.

A vulnerability was found in GNU Binutils due to an integer overflow in the IS_CONTAINED_BY_LMA function within elf.c in libbfd, where an attacker could exploit this flaw by persuading a victim to open a specially crafted file, causing the application to enter an infinite loop and resulting in a denial of service condition.

Отчет

This vulnerability was rated as LOW severity because it requires the victim to open a specially crafted file, it does not lead to system compromise, it can cause the application to enter an infinite loop, resulting in a temporary denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5binutilsNot affected
Red Hat Enterprise Linux 5binutils220Not affected
Red Hat Enterprise Linux 6binutilsWill not fix
Red Hat Enterprise Linux 7binutilsWill not fix
Red Hat Enterprise Linux 8binutilsWill not fix
Red Hat Enterprise Linux 8mingw-binutilsWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=1658949binutils: Integer overflow due to the IS_CONTAINED_BY_LMA macro resulting in a denial of service

EPSS

Процентиль: 79%
0.01977
Низкий

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 7 лет назад

An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils through 2.31. There is an integer overflow and infinite loop caused by the IS_CONTAINED_BY_LMA macro in elf.c.

CVSS3: 5.5
nvd
больше 7 лет назад

An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils through 2.31. There is an integer overflow and infinite loop caused by the IS_CONTAINED_BY_LMA macro in elf.c.

CVSS3: 5.5
debian
больше 7 лет назад

An issue was discovered in the Binary File Descriptor (BFD) library (a ...

CVSS3: 5.5
github
больше 4 лет назад

An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils through 2.31. There is an integer overflow and infinite loop caused by the IS_CONTAINED_BY_LMA macro in elf.c.

CVSS3: 6.5
fstec
больше 7 лет назад

Уязвимость макроса IS_CONTAINED_BY_LMA компонента bfd/elf.c программного средства разработки GNU Binutils, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 79%
0.01977
Низкий

3.3 Low

CVSS3