Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-20651

Опубликовано: 28 дек. 2018
Источник: redhat
CVSS3: 3.3
EPSS Низкий

Описание

A NULL pointer dereference was discovered in elf_link_add_object_symbols in elflink.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31.1. This occurs for a crafted ET_DYN with no program headers. A specially crafted ELF file allows remote attackers to cause a denial of service, as demonstrated by ld.

Отчет

This vulnerability is rated as low severity because it allows an attacker to cause a denial of service through a NULL pointer dereference, this flaw would crash the application, but it does not affect system integrity or data confidentiality. This issue did not affect the versions of binutils as shipped with Red Hat Enterprise Linux 5, 6, and 7 as they did not include the vulnerable code, which was introduced in a newer version of the package.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5binutilsNot affected
Red Hat Enterprise Linux 6binutilsNot affected
Red Hat Enterprise Linux 7binutilsNot affected
Red Hat Enterprise Linux 8binutilsWill not fix
Red Hat Enterprise Linux 8mingw-binutilsWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=1664703binutils: NULL pointer dereference in elf_link_add_object_symbols function resulting in a denial of service

EPSS

Процентиль: 73%
0.0076
Низкий

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 7 лет назад

A NULL pointer dereference was discovered in elf_link_add_object_symbols in elflink.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31.1. This occurs for a crafted ET_DYN with no program headers. A specially crafted ELF file allows remote attackers to cause a denial of service, as demonstrated by ld.

CVSS3: 5.5
nvd
около 7 лет назад

A NULL pointer dereference was discovered in elf_link_add_object_symbols in elflink.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31.1. This occurs for a crafted ET_DYN with no program headers. A specially crafted ELF file allows remote attackers to cause a denial of service, as demonstrated by ld.

CVSS3: 5.5
debian
около 7 лет назад

A NULL pointer dereference was discovered in elf_link_add_object_symbo ...

CVSS3: 5.5
github
больше 3 лет назад

A NULL pointer dereference was discovered in elf_link_add_object_symbols in elflink.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31.1. This occurs for a crafted ET_DYN with no program headers. A specially crafted ELF file allows remote attackers to cause a denial of service, as demonstrated by ld.

CVSS3: 5.5
fstec
около 7 лет назад

Уязвимость функции elf_link_add_object_symbols в GNU Binutils, связанная с разыменованием указателя NULL, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 73%
0.0076
Низкий

3.3 Low

CVSS3