Описание
In GNU Binutils before 2.40, there is a heap-buffer-overflow in the error function bfd_getl32 when called from the strip_main function in strip-new via a crafted file.
A vulnerability was found in the strip utility of binutils. An attacker able to convince a victim to process a specially crafted COFF file by the strip utility can lead to a heap-based buffer overflow, causing the utility to crash.
Отчет
This issue is only triggered when a specially crafted COFF file is processed by the strip utility. The COFF file format is not used in Red Hat Enterprise Linux, the object file format used by default is ELF.
Меры по смягчению последствий
Do not process untrusted files with the strip utility.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | binutils | Out of support scope | ||
| Red Hat Enterprise Linux 7 | binutils | Out of support scope | ||
| Red Hat Enterprise Linux 8 | binutils | Will not fix | ||
| Red Hat Enterprise Linux 8 | gcc-toolset-10-binutils | Will not fix | ||
| Red Hat Enterprise Linux 8 | gcc-toolset-11-binutils | Will not fix | ||
| Red Hat Enterprise Linux 8 | gcc-toolset-12-binutils | Will not fix | ||
| Red Hat Enterprise Linux 9 | binutils | Fix deferred | ||
| Red Hat Enterprise Linux 9 | gcc-toolset-12-binutils | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
5.5 Medium
CVSS3
Связанные уязвимости
In GNU Binutils before 2.40, there is a heap-buffer-overflow in the error function bfd_getl32 when called from the strip_main function in strip-new via a crafted file.
In GNU Binutils before 2.40, there is a heap-buffer-overflow in the error function bfd_getl32 when called from the strip_main function in strip-new via a crafted file.
In GNU Binutils before 2.40 there is a heap-buffer-overflow in the error function bfd_getl32 when called from the strip_main function in strip-new via a crafted file.
In GNU Binutils before 2.40, there is a heap-buffer-overflow in the er ...
In GNU Binutils before 2.40, there is a heap-buffer-overflow in the error function bfd_getl32 when called from the strip_main function in strip-new via a crafted file.
EPSS
5.5 Medium
CVSS3