CVE-2018-1000876Integer Overflow or Wraparound in Binutils

Severity
7.8HIGHNVD
EPSS
0.1%
top 67.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 20
Latest updateMay 13

Description

binutils version 2.32 and earlier contains a Integer Overflow vulnerability in objdump, bfd_get_dynamic_reloc_upper_bound,bfd_canonicalize_dynamic_reloc that can result in Integer overflow trigger heap overflow. Successful exploitation allows execution of arbitrary code.. This attack appear to be exploitable via Local. This vulnerability appears to have been fixed in after commit 3a551c7a1b80fca579461774860574eabfd7f18f.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages5 packages

Also affects: Ubuntu Linux 18.04

🔴Vulnerability Details

3
GHSA
GHSA-qm5c-9m22-x97p: binutils version 22022-05-13
CVEList
CVE-2018-1000876: binutils version 22018-12-20
OSV
CVE-2018-1000876: binutils version 22018-12-20

📋Vendor Advisories

4
Ubuntu
GNU binutils vulnerabilities2021-07-21
Ubuntu
GNU binutils vulnerabilities2020-04-22
Red Hat
binutils: integer overflow leads to heap-based buffer overflow in objdump2018-12-16
Debian
CVE-2018-1000876: binutils - binutils version 2.32 and earlier contains a Integer Overflow vulnerability in o...2018

💬Community

4
Bugzilla
CVE-2018-1000876 binutils: integer overflow leads to heap-based buffer overflow in objdump2019-01-09
Bugzilla
CVE-2018-1000876 CVE-2018-20623 CVE-2018-20651 CVE-2018-20657 CVE-2018-20671 CVE-2018-20673 binutils: various flaws [fedora-all]2019-01-09
Bugzilla
CVE-2018-1000876 CVE-2018-20623 CVE-2018-20651 CVE-2018-20657 CVE-2018-20671 CVE-2018-20673 mingw-binutils: various flaws [epel-all]2019-01-09
Bugzilla
CVE-2018-1000876 CVE-2018-20623 CVE-2018-20651 CVE-2018-20657 CVE-2018-20671 CVE-2018-20673 mingw-binutils: various flaws [fedora-all]2019-01-09
CVE-2018-1000876 — Integer Overflow or Wraparound | cvebase