CVE-2023-25584Out-of-bounds Read in Binutils

CWE-125Out-of-bounds Read8 documents8 sources
Severity
7.1HIGHNVD
CNA6.3
EPSS
0.0%
top 97.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 14

Description

An out-of-bounds read flaw was found in the parse_module function in bfd/vms-alpha.c in Binutils.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:HExploitability: 1.8 | Impact: 5.2

Affected Packages2 packages

NVDgnu/binutils< 2.40
Debiangnu/binutils< 2.39.50.20221224-1+2

Patches

🔴Vulnerability Details

3
OSV
CVE-2023-25584: An out-of-bounds read flaw was found in the parse_module function in bfd/vms-alpha2023-09-14
CVEList
Out of bounds read in parse_module function in bfd/vms-alpha.c2023-09-14
GHSA
GHSA-xgv8-vx7r-x752: An out-of-bounds read flaw was found in the parse_module function in bfd/vms-alpha2023-09-14

📋Vendor Advisories

4
Microsoft
Out of bounds read in parse_module function in bfd/vms-alpha.c2023-09-12
Ubuntu
GNU binutils vulnerabilities2023-05-24
Debian
CVE-2023-25584: binutils - An out-of-bounds read flaw was found in the parse_module function in bfd/vms-alp...2023
Red Hat
binutils: Out of bounds read in parse_module function in bfd/vms-alpha.c2022-12-12
CVE-2023-25584 — Out-of-bounds Read in GNU Binutils | cvebase