Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-3487

Опубликовано: 25 нояб. 2020
Источник: redhat
CVSS3: 0

Описание

There's a flaw in the BFD library of binutils. An attacker who supplies a crafted file to an application linked with BFD, and using the DWARF functionality, could cause an impact to system availability by way of excessive memory consumption.

Отчет

Red Hat Product Security does not consider this to be a vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6binutilsOut of support scope
Red Hat Enterprise Linux 7binutilsOut of support scope
Red Hat Enterprise Linux 8gcc-toolset-10-binutilsWill not fix
Red Hat Enterprise Linux 8gcc-toolset-9-binutilsAffected
Red Hat Enterprise Linux 9binutilsNot affected
Red Hat Enterprise Linux 8binutilsFixedRHSA-2021:436409.11.2021
Red Hat Enterprise Linux 8binutilsFixedRHSA-2021:436409.11.2021

Показывать по

Дополнительная информация

Дефект:
CWE-20->CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1947111binutils: Excessive debug section size can cause excessive memory consumption in bfd's dwarf2.c read_section()

0 Low

CVSS3

Связанные уязвимости

ubuntu
больше 4 лет назад

Rejected reason: Non Security Issue. See the binutils security policy for more details, https://sourceware.org/cgit/binutils-gdb/tree/binutils/SECURITY.txt

nvd
больше 4 лет назад

Rejected reason: Non Security Issue. See the binutils security policy for more details, https://sourceware.org/cgit/binutils-gdb/tree/binutils/SECURITY.txt

CVSS3: 6.5
msrc
больше 4 лет назад

Описание отсутствует

CVSS3: 6.5
github
больше 3 лет назад

There's a flaw in the BFD library of binutils in versions before 2.36. An attacker who supplies a crafted file to an application linked with BFD, and using the DWARF functionality, could cause an impact to system availability by way of excessive memory consumption.

CVSS3: 6.5
fstec
около 5 лет назад

Уязвимость функции read_section() компонента dwarf2.c программного средства разработки GNU Binutils, позволяющая нарушителю вызвать отказ в обслуживании

0 Low

CVSS3