Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-45703

Опубликовано: 17 нояб. 2022
Источник: redhat
EPSS Низкий

Описание

Heap buffer overflow vulnerability in binutils readelf before 2.40 via function display_debug_section in file readelf.c.

A heap-based buffer overflow vulnerability was found in display_debug_section in binutils-2.40. An attacker using a specially crafted payload to trigger a buffer overflow resulting in damage to availability, confidentiality and integrity.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6binutilsNot affected
Red Hat Enterprise Linux 7binutilsNot affected
Red Hat Enterprise Linux 7gdbNot affected
Red Hat Enterprise Linux 8binutilsNot affected
Red Hat Enterprise Linux 8gcc-toolset-11-binutilsNot affected
Red Hat Enterprise Linux 8gcc-toolset-11-gdbNot affected
Red Hat Enterprise Linux 8gcc-toolset-12-binutilsNot affected
Red Hat Enterprise Linux 8gcc-toolset-12-gdbNot affected
Red Hat Enterprise Linux 8gcc-toolset-13-binutilsNot affected
Red Hat Enterprise Linux 8gcc-toolset-13-gdbNot affected

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=2234012binutils: heap-based buffer overflow in display_debug_section() in readelf.c

EPSS

Процентиль: 45%
0.00549
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 3 лет назад

Heap buffer overflow vulnerability in binutils readelf before 2.40 via function display_debug_section in file readelf.c.

CVSS3: 7.8
nvd
около 3 лет назад

Heap buffer overflow vulnerability in binutils readelf before 2.40 via function display_debug_section in file readelf.c.

CVSS3: 7.8
debian
около 3 лет назад

Heap buffer overflow vulnerability in binutils readelf before 2.40 via ...

CVSS3: 7.8
github
около 3 лет назад

Heap buffer overflow vulnerability in binutils readelf before 2.40 via function display_debug_section in file readelf.c.

CVSS3: 7.8
fstec
почти 4 года назад

Уязвимость функции display_debug_section компонента readelf.c программного средства разработки GNU Binutils, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

EPSS

Процентиль: 45%
0.00549
Низкий