CVE-2018-7643Integer Overflow or Wraparound in Binutils

Severity
7.8HIGHNVD
EPSS
0.2%
top 61.22%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 2
Latest updateMay 13

Description

The display_debug_ranges function in dwarf.c in GNU Binutils 2.30 allows remote attackers to cause a denial of service (integer overflow and application crash) or possibly have unspecified other impact via a crafted ELF file, as demonstrated by objdump.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages5 packages

🔴Vulnerability Details

3
GHSA
GHSA-v67x-fvwh-9f63: The display_debug_ranges function in dwarf2022-05-13
OSV
CVE-2018-7643: The display_debug_ranges function in dwarf2018-03-02
CVEList
CVE-2018-7643: The display_debug_ranges function in dwarf2018-03-02

📋Vendor Advisories

3
Ubuntu
GNU binutils vulnerabilities2021-07-21
Red Hat
binutils: Integer overflow in the display_debug_ranges function resulting in crash2018-03-01
Debian
CVE-2018-7643: binutils - The display_debug_ranges function in dwarf.c in GNU Binutils 2.30 allows remote ...2018

💬Community

3
Bugzilla
CVE-2018-7643 binutils: Integer overflow in the display_debug_ranges function resulting in crash2018-03-08
Bugzilla
CVE-2018-7570 CVE-2018-7642 CVE-2018-7643 mingw-binutils: various flaws [epel-all]2018-03-05
Bugzilla
CVE-2018-7570 CVE-2018-7642 CVE-2018-7643 binutils: various flaws [fedora-all]2018-03-05
CVE-2018-7643 — Integer Overflow or Wraparound | cvebase