[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

256040

 
 

909

 
 

199103

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2023-2023-334 --- binutils

ID: oval:org.secpod.oval:def:19500375Date: (C)2024-01-04   (M)2024-04-17
Class: PATCHFamily: unix




Heap buffer overflow vulnerability in binutils readelf before 2.40 via function display_debug_section in file readelf.c. An issue was discovered in Binutils addr2line before 2.39.3, function parse_module contains multiple out of bound reads which may cause a denial of service or other unspecified impacts. An issue was discovered Binutils objdump before 2.39.3 allows attackers to cause a denial of service or other unspecified impacts via function bfd_mach_o_get_synthetic_symtab in match-o.c. An issue was discovered Binutils objdump before 2.39.3 allows attackers to cause a denial of service or other unspecified impacts via function compare_symbols. GNU Binutils before 2.40 was discovered to contain an excessive memory consumption vulnerability via the function load_separate_debug_files at dwarf2.c. The attacker could supply a crafted ELF file and cause a DNS attack. GNU Binutils before 2.40 was discovered to contain an excessive memory consumption vulnerability via the function bfd_dwarf2_find_nearest_line_with_alt at dwarf2.c. The attacker could supply a crafted ELF file and cause a DNS attack. GNU Binutils before 2.40 was discovered to contain a memory leak vulnerability var the function find_abstract_instance in dwarf2.c

Platform:
Amazon Linux 2023
Product:
binutils
Reference:
ALAS2023-2023-334
CVE-2022-45703
CVE-2022-47673
CVE-2022-47695
CVE-2022-47696
CVE-2022-48063
CVE-2022-48064
CVE-2022-48065
CVE    7
CVE-2022-48063
CVE-2022-48065
CVE-2022-48064
CVE-2022-45703
...
CPE    1
cpe:/a:sourceware:binutils

© SecPod Technologies