CVE-2023-1972

Name
CVE-2023-1972
Description
A potential heap based buffer overflow was found in _bfd_elf_slurp_version_tables() in bfd/elf.c. This may lead to loss of availability.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://bugzilla.redhat.com/show_bug.cgi?id=2185646
MISC https://sourceware.org/bugzilla/show_bug.cgi?id=30285
GENTOO https://security.gentoo.org/glsa/202309-15

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:gnu:binutils:*:*:*:*:*:*:*:* binutils >= None <= 2.40
cpe:2.3:a:gnu:binutils:*:*:*:*:*:*:*:* binutils >= 2.35 <= 2.40

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
binutils 3.17-main 2.39-r2 Ariadne Conill <ariadne@dereferenced.org> possibly vulnerable
binutils 3.16-main 2.38-r3 Ariadne Conill <ariadne@dereferenced.org> possibly vulnerable
binutils 3.15-main 2.37-r3 Ariadne Conill <ariadne@dereferenced.org> possibly vulnerable
binutils 3.18-main 2.40-r7 Ariadne Conill <ariadne@dereferenced.org> fixed