Updated: 2024-11-23 04:56:49.442375
Description:
In GNU Binutils 2.30, there's an integer overflow in the function load_specific_debug_section() in objdump.c, which results in `malloc()` with 0 size. A crafted ELF file allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.
Links | NIST | CIRCL | RHEL | Ubuntu |
Severity | Score | |
---|---|---|
CVSS Version 2.x | MEDIUM | 6.8 |
CVSS Version 3.x | HIGH | 7.8 |
OS name | Project name | Version | Score | Severity | Status | Errata | Last updated | Statement |
---|---|---|---|---|---|---|---|---|
CentOS 6 ELS | binutils | 2.20 | 7.8 | HIGH | Released | CLSA-2021:1640621287 | 2022-05-05 12:03:22 | |
CloudLinux 6 ELS | binutils | 2.20 | 7.8 | HIGH | Released | CLSA-2021:1639670535 | 2021-12-27 14:17:46 | |
Oracle Linux 6 ELS | binutils | 2.20 | 7.8 | HIGH | Released | CLSA-2021:1639670584 | 2021-12-16 15:55:40 | |
Ubuntu 16.04 ELS | binutils | 2.26 | 7.8 | HIGH | Released | CLSA-2021:1635459139 | 2021-12-16 10:40:04 | |
Ubuntu 18.04 ELS | binutils | 2.30-21 | 7.8 | HIGH | Not Vulnerable | 2023-10-11 05:08:01 |