Описание
An issue was discovered function make_tempdir, and make_tempname in bucomm.c in Binutils 2.34 thru 2.38, allows attackers to cause a denial of service due to memory leaks.
A memory leak was found in binutils in the make_tempdir and make_tempname functions. This flaw allows an attacker to use a set of steps to trigger a memory leak and perform a denial of service, resulting in a loss of the system's availability.
Отчет
The issue is classified as low severity primarily because binutils is not typically exposed to untrusted inputs in most environments, limiting its exploitation potential. The memory leak in bucomm.c only triggers during the parsing of malformed files, which would require an attacker to convince a user to process a malicious file. Moreover, binutils does not handle privileged operations, meaning exploitation is unlikely to lead to system compromise or escalation of privileges. Additionally, the impact is localized to the application itself, without affecting the broader system or network security.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 6 | binutils | Out of support scope | ||
Red Hat Enterprise Linux 7 | binutils | Out of support scope | ||
Red Hat Enterprise Linux 7 | gdb | Out of support scope | ||
Red Hat Enterprise Linux 8 | binutils | Will not fix | ||
Red Hat Enterprise Linux 8 | gcc-toolset-11-binutils | Fix deferred | ||
Red Hat Enterprise Linux 8 | gcc-toolset-11-gdb | Not affected | ||
Red Hat Enterprise Linux 8 | gcc-toolset-12-binutils | Fix deferred | ||
Red Hat Enterprise Linux 8 | gcc-toolset-12-gdb | Not affected | ||
Red Hat Enterprise Linux 8 | gcc-toolset-13-binutils | Fix deferred | ||
Red Hat Enterprise Linux 8 | gcc-toolset-13-gdb | Affected |
Показывать по
Дополнительная информация
Статус:
5.5 Medium
CVSS3
Связанные уязвимости
An issue was discovered function make_tempdir, and make_tempname in bucomm.c in Binutils 2.34 thru 2.38, allows attackers to cause a denial of service due to memory leaks.
An issue was discovered function make_tempdir, and make_tempname in bucomm.c in Binutils 2.34 thru 2.38, allows attackers to cause a denial of service due to memory leaks.
An issue was discovered function make_tempdir, and make_tempname in bu ...
An issue was discovered function make_tempdir, and make_tempname in bucomm.c in Binutils 2.34 thru 2.38, allows attackers to cause a denial of service due to memory leaks.
5.5 Medium
CVSS3