Описание
A potential heap based buffer overflow was found in _bfd_elf_slurp_version_tables() in bfd/elf.c. This may lead to loss of availability.
A potential heap-based buffer overflow was found in binutils in the _bfd_elf_slurp_version_tables() function in bfd/elf.c. This issue may lead to a loss of availability.
Отчет
This issue is classified with a low severity primarily because binutils is not typically exposed to untrusted inputs in most environments, limiting the possibility of exploitation. Additionally, this heap-based buffer overflow is only triggered during the parsing of a specially crafted file, requiring an attacker to convince a user to process this file with objdump. Furthermore, binutils does not handle privileged operations, meaning that exploitation is unlikely to lead to system compromise or escalation of privileges. Also, the impact is limited to the application itself, without affecting the broader system or network security.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 6 | binutils | Out of support scope | ||
Red Hat Enterprise Linux 7 | binutils | Fix deferred | ||
Red Hat Enterprise Linux 8 | binutils | Fix deferred | ||
Red Hat Enterprise Linux 8 | gcc-toolset-11-binutils | Fix deferred | ||
Red Hat Enterprise Linux 8 | gcc-toolset-12-binutils | Fix deferred | ||
Red Hat Enterprise Linux 9 | binutils | Fix deferred | ||
Red Hat Enterprise Linux 9 | gcc-toolset-12-binutils | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
2.5 Low
CVSS3
Связанные уязвимости
A potential heap based buffer overflow was found in _bfd_elf_slurp_version_tables() in bfd/elf.c. This may lead to loss of availability.
A potential heap based buffer overflow was found in _bfd_elf_slurp_version_tables() in bfd/elf.c. This may lead to loss of availability.
A potential heap based buffer overflow was found in _bfd_elf_slurp_ver ...
A potential heap based buffer overflow was found in _bfd_elf_slurp_version_tables() in bfd/elf.c. This may lead to loss of availability.
EPSS
2.5 Low
CVSS3