Back

CRITICAL

binutils: heap-based buffer overflow in finish_stab in stabs.c

Published Jun 23, 2018

Description

finish_stab in stabs.c in GNU Binutils 2.30 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds write of 8 bytes. This can occur during execution of objdump.

Affected products

Remediation

Red Hat statement

This is a vulnerability affecting binutils, a suite of tools for managing binaries on a linux system; as these tools are used by developers in compilation and debugging, the expected use case is a local user examining object files on a local filesystem, or using ssh to log in. Because of differences in how upstream sources and other vendors provide these utilities, other sources might report the impact of this flaw differently. However, while it is possible for specifically-crafted input to crash binutils via this flaw, Red Hat does not assess that it represents a significant security impact.

Metrics

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 23, 2018
Updated Aug 5, 2024
Reserved Jun 23, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Apr 11, 2018