Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-14250

Опубликовано: 09 авг. 2019
Источник: redhat
CVSS3: 3.3
EPSS Низкий

Описание

An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. simple_object_elf_match in simple-object-elf.c does not check for a zero shstrndx value, leading to an integer overflow and resultant heap-based buffer overflow.

Отчет

This issue resides on libiberty code, libiberty is part of GNU project and contains several utilities being distributed by gcc and binutils packages. This flaws affects binutils versions as shipped with Red Hat Enterprise Linux 5, 6, 7 and 8 and also gcc versions as shipped with Red Hat Enterprise Linux 5, 6 ,7 and 8. Versions of gcc shipped with Red Hat Developers Tool Set 7 and 8 are also affected. Red Hat Product Security scored the impact of this bug to "Low" for the following reasons:

  1. This flaw requires the attacker to attacker to convince a local user to run a specially crafted ELF binary.
  2. The local user must have access to a vulnerable application that incorporates a vulnerable version of libiberty, a part of gnuutils.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5binutilsOut of support scope
Red Hat Enterprise Linux 6binutilsOut of support scope
Red Hat Enterprise Linux 7binutilsFix deferred
Red Hat Enterprise Linux 7gccFix deferred
Red Hat Enterprise Linux 8binutilsFix deferred
Red Hat Enterprise Linux 8gccFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-20->CWE-190->CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1739490binutils: integer overflow in simple-object-elf.c leads to a heap-based buffer overflow

EPSS

Процентиль: 36%
0.00151
Низкий

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 6 лет назад

An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. simple_object_elf_match in simple-object-elf.c does not check for a zero shstrndx value, leading to an integer overflow and resultant heap-based buffer overflow.

CVSS3: 5.5
nvd
около 6 лет назад

An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. simple_object_elf_match in simple-object-elf.c does not check for a zero shstrndx value, leading to an integer overflow and resultant heap-based buffer overflow.

CVSS3: 5.5
msrc
около 5 лет назад

Описание отсутствует

CVSS3: 5.5
debian
около 6 лет назад

An issue was discovered in GNU libiberty, as distributed in GNU Binuti ...

suse-cvrf
больше 3 лет назад

Security update for gcc48

EPSS

Процентиль: 36%
0.00151
Низкий

3.3 Low

CVSS3