Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-25584

Опубликовано: 12 дек. 2022
Источник: redhat
CVSS3: 6.3
EPSS Низкий

Описание

An out-of-bounds read flaw was found in the parse_module function in bfd/vms-alpha.c in Binutils.

Отчет

The issue is classified as low severity primarily because binutils is not typically exposed to untrusted inputs in most environments, limiting its exploitation potential. The buffer overflow in vms-alpha.c only triggers during the parsing of malformed files, which would require an attacker to convince a user to process a malicious binary file. Moreover, binutils does not handle privileged operations, meaning exploitation is unlikely to lead to system compromise or escalation of privileges. Additionally, the impact is localized to the application itself, without affecting the broader system or network security.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6binutilsWill not fix
Red Hat Enterprise Linux 7binutilsWill not fix
Red Hat Enterprise Linux 8binutilsFix deferred
Red Hat Enterprise Linux 8gcc-toolset-11-binutilsFix deferred
Red Hat Enterprise Linux 8gcc-toolset-11-gdbNot affected
Red Hat Enterprise Linux 8gcc-toolset-12-binutilsFix deferred
Red Hat Enterprise Linux 8gcc-toolset-12-gdbNot affected
Red Hat Enterprise Linux 9binutilsNot affected
Red Hat Enterprise Linux 9gcc-toolset-12-binutilsNot affected
Red Hat Enterprise Linux 9gcc-toolset-12-gdbNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2167467binutils: Out of bounds read in parse_module function in bfd/vms-alpha.c

EPSS

Процентиль: 2%
0.00014
Низкий

6.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.3
ubuntu
больше 2 лет назад

An out-of-bounds read flaw was found in the parse_module function in bfd/vms-alpha.c in Binutils.

CVSS3: 6.3
nvd
больше 2 лет назад

An out-of-bounds read flaw was found in the parse_module function in bfd/vms-alpha.c in Binutils.

CVSS3: 6.3
msrc
10 месяцев назад

Out of bounds read in parse_module function in bfd/vms-alpha.c

CVSS3: 6.3
debian
больше 2 лет назад

An out-of-bounds read flaw was found in the parse_module function in b ...

CVSS3: 6.3
github
больше 2 лет назад

An out-of-bounds read flaw was found in the parse_module function in bfd/vms-alpha.c in Binutils.

EPSS

Процентиль: 2%
0.00014
Низкий

6.3 Medium

CVSS3