CVE-2018-1000876

Updated: 2023-02-28 19:08:58.510349

Description:

binutils version 2.32 and earlier contains a Integer Overflow vulnerability in objdump, bfd_get_dynamic_reloc_upper_bound,bfd_canonicalize_dynamic_reloc that can result in Integer overflow trigger heap overflow. Successful exploitation allows execution of arbitrary code.. This attack appear to be exploitable via Local. This vulnerability appears to have been fixed in after commit 3a551c7a1b80fca579461774860574eabfd7f18f.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x MEDIUM 4.6
CVSS Version 3.x HIGH 7.8

Status

OS name Project name Version Score Severity Status Errata Last updated
CentOS 6 ELS binutils 2.20 7.8 HIGH Released CLSA-2021:1640621287 2022-05-05 12:03:38
CloudLinux 6 ELS binutils 2.20 7.8 HIGH Released CLSA-2021:1639670535 2021-12-27 14:17:27
Oracle Linux 6 ELS binutils 2.20 7.8 HIGH Released CLSA-2021:1639670584 2021-12-16 15:55:25
Ubuntu 16.04 ELS binutils 2.26 7.8 HIGH Released CLSA-2021:1635459139 2021-12-09 07:57:03