Back

MEDIUM

binutils: invalid memory address dereference in read_reloc in reloc.c

Published Oct 15, 2018

Description

An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. An invalid memory address dereference was discovered in read_reloc in reloc.c. The vulnerability causes a segmentation fault and application crash, which leads to denial of service, as demonstrated by objdump, because of missing _bfd_clear_contents bounds checking.

Affected products

Remediation

Red Hat statement

Red Hat has determined this flaw to be of low impact as successful exploitation results in a crash (denial of service) of the application utilizing the binutils library and does not impact system-wide stability or lead to arbitrary code execution or memory corruption.

Metrics

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 15, 2018
Updated Aug 5, 2024
Reserved Oct 14, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Oct 13, 2018