CVE-2023-25585

Severity
5.5MEDIUM
EPSS
0.0%
top 94.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 14

Description

A flaw was found in Binutils. The use of an uninitialized field in the struct module *module may lead to application crash and local denial of service.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.0 | Impact: 3.6

Affected Packages2 packages

Debianbinutils< 2.39.50.20221224-1+2
NVDgnu/binutils2.40

Patches

🔴Vulnerability Details

3
OSV
CVE-2023-25585: A flaw was found in Binutils2023-09-14
GHSA
GHSA-7787-4vjc-4737: A flaw was found in Binutils2023-09-14
CVEList
Field `file_table` of `struct module *module` is uninitialized2023-09-14

📋Vendor Advisories

4
Microsoft
Field `file_table` of `struct module *module` is uninitialized2023-09-12
Ubuntu
GNU binutils vulnerabilities2023-05-24
Debian
CVE-2023-25585: binutils - A flaw was found in Binutils. The use of an uninitialized field in the struct mo...2023
Red Hat
binutils: Field `file_table` of `struct module *module` is uninitialized2022-12-12
CVE-2023-25585 (MEDIUM CVSS 5.5) | A flaw was found in Binutils | cvebase.io