Описание
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has an aout_link_add_symbols function in bfd/aoutx.h that is vulnerable to a heap-based buffer over-read (off-by-one) because of an incomplete check for invalid string offsets while loading symbols, leading to a GNU linker (ld) program crash.
| Релиз | Статус | Примечание |
|---|---|---|
| artful | not-affected | 2.28-1ubuntu1 |
| bionic | not-affected | 2.28-1ubuntu1 |
| cosmic | not-affected | 2.28-1ubuntu1 |
| devel | not-affected | 2.28-1ubuntu1 |
| disco | not-affected | 2.28-1ubuntu1 |
| eoan | not-affected | 2.28-1ubuntu1 |
| esm-infra-legacy/trusty | needed | |
| esm-infra/bionic | not-affected | 2.28-1ubuntu1 |
| esm-infra/focal | not-affected | 2.28-1ubuntu1 |
| esm-infra/xenial | released | 2.26.1-1ubuntu1~16.04.8+esm1 |
Показывать по
5 Medium
CVSS2
7.5 High
CVSS3
Связанные уязвимости
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has an aout_link_add_symbols function in bfd/aoutx.h that is vulnerable to a heap-based buffer over-read (off-by-one) because of an incomplete check for invalid string offsets while loading symbols, leading to a GNU linker (ld) program crash.
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has an aout_link_add_symbols function in bfd/aoutx.h that is vulnerable to a heap-based buffer over-read (off-by-one) because of an incomplete check for invalid string offsets while loading symbols, leading to a GNU linker (ld) program crash.
The Binary File Descriptor (BFD) library (aka libbfd), as distributed ...
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has an aout_link_add_symbols function in bfd/aoutx.h that is vulnerable to a heap-based buffer over-read (off-by-one) because of an incomplete check for invalid string offsets while loading symbols, leading to a GNU linker (ld) program crash.
5 Medium
CVSS2
7.5 High
CVSS3