ZeroHour

CVE-2018-7568

PoC
CVSS 3.0
5.5 medium
EPSS
2%p79
Published
()
Modified
Description

The parse_die function in dwarf1.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to cause a denial of service (integer overflow and application crash) via an ELF file with corrupt dwarf1 debug information, as demonstrated by nm.

Vendors
gnuredhat
Products
binutils, enterprise linux desktop, enterprise linux server, enterprise linux workstation
Weakness
CWE-190
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.