CVE-2018-20002

Name
CVE-2018-20002
Description
The _bfd_generic_read_minisymbols function in syms.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31, has a memory leak via a crafted ELF file, leading to a denial of service (memory consumption), as demonstrated by nm.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Third Party Advisory https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=c2f5dc30afa34696f2da0081c4ac50b958ecb0e9
Exploit https://sourceware.org/bugzilla/show_bug.cgi?id=23952
Third Party Advisory http://www.securityfocus.com/bid/106142
Patch https://security.netapp.com/advisory/ntap-20190221-0004/
Third Party Advisory https://support.f5.com/csp/article/K62602089
GENTOO https://security.gentoo.org/glsa/201908-01
UBUNTU https://usn.ubuntu.com/4336-1/

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:gnu:binutils:2.31:*:*:*:*:*:*:* binutils == None == 2.31

Vulnerable and fixed packages

Source package Branch Version Maintainer Status