Описание
A vulnerability has been found in GNU Binutils 2.44 and classified as problematic. This vulnerability affects the function bfd_elf_get_str_section of the file bfd/elf.c of the component BFD Library. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The name of the patch is db856d41004301b3a56438efd957ef5cabb91530. It is recommended to apply a patch to fix this issue.
A flaw was found in binutils. The bfd_elf_get_str_section
function in the BFD Library’s bfd/elf.c
file exhibits a null pointer dereference due to manipulation, potentially allowing a local attacker to trigger a denial of service. This occurs when processing specially crafted ELF files. The resulting null pointer dereference can lead to program termination.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 10 | binutils | Not affected | ||
Red Hat Enterprise Linux 10 | gcc-toolset-15-binutils | Fix deferred | ||
Red Hat Enterprise Linux 10 | gdb | Not affected | ||
Red Hat Enterprise Linux 10 | mingw-binutils | Not affected | ||
Red Hat Enterprise Linux 6 | binutils | Not affected | ||
Red Hat Enterprise Linux 7 | binutils | Not affected | ||
Red Hat Enterprise Linux 7 | gdb | Not affected | ||
Red Hat Enterprise Linux 8 | binutils | Not affected | ||
Red Hat Enterprise Linux 8 | gcc-toolset-13-binutils | Not affected | ||
Red Hat Enterprise Linux 8 | gcc-toolset-13-gdb | Not affected |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
3.3 Low
CVSS3
Связанные уязвимости
A vulnerability has been found in GNU Binutils 2.44 and classified as problematic. This vulnerability affects the function bfd_elf_get_str_section of the file bfd/elf.c of the component BFD Library. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The name of the patch is db856d41004301b3a56438efd957ef5cabb91530. It is recommended to apply a patch to fix this issue.
A vulnerability has been found in GNU Binutils 2.44 and classified as problematic. This vulnerability affects the function bfd_elf_get_str_section of the file bfd/elf.c of the component BFD Library. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The name of the patch is db856d41004301b3a56438efd957ef5cabb91530. It is recommended to apply a patch to fix this issue.
A vulnerability has been found in GNU Binutils 2.44 and classified as ...
A vulnerability has been found in GNU Binutils 2.44 and classified as problematic. This vulnerability affects the function bfd_elf_get_str_section of the file bfd/elf.c of the component BFD Library. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The name of the patch is db856d41004301b3a56438efd957ef5cabb91530. It is recommended to apply a patch to fix this issue.
EPSS
3.3 Low
CVSS3