Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-1972

Опубликовано: 10 апр. 2023
Источник: redhat
CVSS3: 2.5
EPSS Низкий

Описание

A potential heap based buffer overflow was found in _bfd_elf_slurp_version_tables() in bfd/elf.c. This may lead to loss of availability.

A potential heap-based buffer overflow was found in binutils in the _bfd_elf_slurp_version_tables() function in bfd/elf.c. This issue may lead to a loss of availability.

Отчет

This issue is classified with a low severity primarily because binutils is not typically exposed to untrusted inputs in most environments, limiting the possibility of exploitation. Additionally, this heap-based buffer overflow is only triggered during the parsing of a specially crafted file, requiring an attacker to convince a user to process this file with objdump. Furthermore, binutils does not handle privileged operations, meaning that exploitation is unlikely to lead to system compromise or escalation of privileges. Also, the impact is limited to the application itself, without affecting the broader system or network security.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6binutilsOut of support scope
Red Hat Enterprise Linux 7binutilsFix deferred
Red Hat Enterprise Linux 8binutilsFix deferred
Red Hat Enterprise Linux 8gcc-toolset-11-binutilsFix deferred
Red Hat Enterprise Linux 8gcc-toolset-12-binutilsFix deferred
Red Hat Enterprise Linux 9binutilsFix deferred
Red Hat Enterprise Linux 9gcc-toolset-12-binutilsFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-119->CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2185646binutils: Illegal memory access when accessing a zer0-lengthverdef table

EPSS

Процентиль: 14%
0.00045
Низкий

2.5 Low

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 2 лет назад

A potential heap based buffer overflow was found in _bfd_elf_slurp_version_tables() in bfd/elf.c. This may lead to loss of availability.

CVSS3: 6.5
nvd
около 2 лет назад

A potential heap based buffer overflow was found in _bfd_elf_slurp_version_tables() in bfd/elf.c. This may lead to loss of availability.

CVSS3: 6.5
msrc
6 месяцев назад

Описание отсутствует

CVSS3: 6.5
debian
около 2 лет назад

A potential heap based buffer overflow was found in _bfd_elf_slurp_ver ...

CVSS3: 6.5
github
около 2 лет назад

A potential heap based buffer overflow was found in _bfd_elf_slurp_version_tables() in bfd/elf.c. This may lead to loss of availability.

EPSS

Процентиль: 14%
0.00045
Низкий

2.5 Low

CVSS3