CVE-2018-10534Out-of-bounds Write in Binutils

CWE-787Out-of-bounds Write12 documents8 sources
Severity
5.5MEDIUMNVD
EPSS
0.2%
top 60.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 29
Latest updateMay 14

Description

The _bfd_XX_bfd_copy_private_bfd_data_common function in peXXigen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, processes a negative Data Directory size with an unbounded loop that increases the value of (external_IMAGE_DEBUG_DIRECTORY) *edd so that the address exceeds its own memory region, resulting in an out-of-bounds memory write, as demonstrated by objcopy copying private info with _bfd_pex64_bfd_copy_private_bfd_data_common in pex64igen.c.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages5 packages

🔴Vulnerability Details

3
GHSA
GHSA-672m-f2rr-8wvq: The _bfd_XX_bfd_copy_private_bfd_data_common function in peXXigen2022-05-14
CVEList
CVE-2018-10534: The _bfd_XX_bfd_copy_private_bfd_data_common function in peXXigen2018-04-29
OSV
CVE-2018-10534: The _bfd_XX_bfd_copy_private_bfd_data_common function in peXXigen2018-04-29

📋Vendor Advisories

4
Ubuntu
GNU binutils vulnerabilities2021-07-21
Ubuntu
GNU binutils vulnerabilities2020-04-22
Red Hat
binutils: out of bounds memory write in peXXigen.c files2018-04-24
Debian
CVE-2018-10534: binutils - The _bfd_XX_bfd_copy_private_bfd_data_common function in peXXigen.c in the Binar...2018

💬Community

4
Bugzilla
CVE-2018-10534 CVE-2018-10535 mingw-binutils: various flaws [epel-all]2018-05-03
Bugzilla
CVE-2018-10534 CVE-2018-10535 binutils: various flaws [fedora-all]2018-05-03
Bugzilla
CVE-2018-10534 CVE-2018-10535 mingw-binutils: various flaws [fedora-all]2018-05-03
Bugzilla
CVE-2018-10534 binutils: out of bounds memory write in peXXigen.c files2018-05-03
CVE-2018-10534 — Out-of-bounds Write in GNU Binutils | cvebase