cbcvebase.
CVE-2018-6759
published 2018-02-06

CVE-2018-6759: The bfd_get_debug_link_info_1 function in opncls.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, has an…

PriorityP419medium5.5CVSS 3.0
AVLACLPRNUIRSUCNINAH
EPSS
2.09%
79.7th percentile
The bfd_get_debug_link_info_1 function in opncls.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, has an unchecked strnlen operation. Remote attackers could leverage this vulnerability to cause a denial of service (segmentation fault) via a crafted ELF file.

Affected

6 ranges
VendorProductVersion rangeFixed in
debianbinutils< binutils 2.30-3 (bookworm)binutils 2.30-3 (bookworm)
gnubinutils
gnubinutils>= 0 < 2.30-32.30-3
gnubinutils>= 0 < 2.30-32.30-3
gnubinutils>= 0 < 2.30-32.30-3
gnubinutils>= 0 < 2.30-32.30-3

CVSS provenance

nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.