Note:
This project will be discontinued after December 13, 2021. [more]
2018-02-02
In GNU Binutils 2.30, there's an integer overflow in the function load_specific_debug_section() in objdump.c, which results in `malloc()` with 0 size. A crafted ELF file allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.
Products | Binutils |
Type | Integer Overflow or Wraparound (CWE-190) |
First patch | - None (likely due to unavailable code) |
Links |
• http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00072.html
• http://www.securityfocus.com/bid/102985 • https://sourceware.org/bugzilla/show_bug.cgi?id=22769 • https://security.gentoo.org/glsa/201811-17 |