CVE-2018-7569Integer Overflow or Wraparound in Binutils

Severity
5.5MEDIUMNVD
EPSS
0.1%
top 64.81%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 28
Latest updateMay 13

Description

dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to cause a denial of service (integer underflow or overflow, and application crash) via an ELF file with a corrupt DWARF FORM block, as demonstrated by nm.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages5 packages

Patches

🔴Vulnerability Details

3
GHSA
GHSA-q9f4-96w8-25fw: dwarf22022-05-13
OSV
CVE-2018-7569: dwarf22018-02-28
CVEList
CVE-2018-7569: dwarf22018-02-28

📋Vendor Advisories

3
Ubuntu
GNU binutils vulnerabilities2021-07-21
Red Hat
binutils: integer underflow or overflow via an ELF file with a corrupt DWARF FORM block in libbfd library2018-02-26
Debian
CVE-2018-7569: binutils - dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distribute...2018

💬Community

3
Bugzilla
CVE-2018-7569 mingw-binutils: binutils: integer underflow or overflow via an ELF file with a corrupt DWARF FORM block in libbfd library [epel-all]2018-03-05
Bugzilla
CVE-2018-7569 binutils: integer underflow or overflow via an ELF file with a corrupt DWARF FORM block in libbfd library [fedora-all]2018-03-05
Bugzilla
CVE-2018-7569 binutils: integer underflow or overflow via an ELF file with a corrupt DWARF FORM block in libbfd library2018-03-05
CVE-2018-7569 — Integer Overflow or Wraparound | cvebase