Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-1000876

Опубликовано: 20 дек. 2018
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 4.6
CVSS3: 7.8

Описание

binutils version 2.32 and earlier contains a Integer Overflow vulnerability in objdump, bfd_get_dynamic_reloc_upper_bound,bfd_canonicalize_dynamic_reloc that can result in Integer overflow trigger heap overflow. Successful exploitation allows execution of arbitrary code.. This attack appear to be exploitable via Local. This vulnerability appears to have been fixed in after commit 3a551c7a1b80fca579461774860574eabfd7f18f.

РелизСтатусПримечание
bionic

released

2.30-21ubuntu1~18.04.3
cosmic

ignored

end of life
devel

not-affected

2.32-8ubuntu1
disco

not-affected

2.32-7ubuntu4
eoan

not-affected

2.32-8ubuntu1
esm-infra-legacy/trusty

needed

esm-infra/bionic

released

2.30-21ubuntu1~18.04.3
esm-infra/focal

not-affected

2.32-8ubuntu1
esm-infra/xenial

released

2.26.1-1ubuntu1~16.04.8+esm1
focal

not-affected

2.32-8ubuntu1

Показывать по

EPSS

Процентиль: 33%
0.00133
Низкий

4.6 Medium

CVSS2

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 4
redhat
около 7 лет назад

binutils version 2.32 and earlier contains a Integer Overflow vulnerability in objdump, bfd_get_dynamic_reloc_upper_bound,bfd_canonicalize_dynamic_reloc that can result in Integer overflow trigger heap overflow. Successful exploitation allows execution of arbitrary code.. This attack appear to be exploitable via Local. This vulnerability appears to have been fixed in after commit 3a551c7a1b80fca579461774860574eabfd7f18f.

CVSS3: 7.8
nvd
около 7 лет назад

binutils version 2.32 and earlier contains a Integer Overflow vulnerability in objdump, bfd_get_dynamic_reloc_upper_bound,bfd_canonicalize_dynamic_reloc that can result in Integer overflow trigger heap overflow. Successful exploitation allows execution of arbitrary code.. This attack appear to be exploitable via Local. This vulnerability appears to have been fixed in after commit 3a551c7a1b80fca579461774860574eabfd7f18f.

CVSS3: 7.8
debian
около 7 лет назад

binutils version 2.32 and earlier contains a Integer Overflow vulnerab ...

CVSS3: 7.8
github
больше 3 лет назад

binutils version 2.32 and earlier contains a Integer Overflow vulnerability in objdump, bfd_get_dynamic_reloc_upper_bound,bfd_canonicalize_dynamic_reloc that can result in Integer overflow trigger heap overflow. Successful exploitation allows execution of arbitrary code.. This attack appear to be exploitable via Local. This vulnerability appears to have been fixed in after commit 3a551c7a1b80fca579461774860574eabfd7f18f.

CVSS3: 7.8
fstec
около 7 лет назад

Уязвимость функции disassemble_data() компонента objdump.c программного средства разработки GNU Binutils, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

EPSS

Процентиль: 33%
0.00133
Низкий

4.6 Medium

CVSS2

7.8 High

CVSS3