CVE-2024-57360
published 2025-01-21CVE-2024-57360: https://www.gnu.org/software/binutils/ nm >=2.43 is affected by: Incorrect Access Control. The type of exploitation is: local. The component is: `nm…
PriorityP419medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.25%
16.3th percentile
https://www.gnu.org/software/binutils/ nm >=2.43 is affected by: Incorrect Access Control. The type of exploitation is: local. The component is: `nm --without-symbol-version` function.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | binutils | < binutils 2.43.50.20241221-1 (forky) | binutils 2.43.50.20241221-1 (forky) |
| gnu | binutils | >= 0 < 2.43.50.20241221-1 | 2.43.50.20241221-1 |
| gnu | binutils | >= 0 < 2.43.50.20241221-1 | 2.43.50.20241221-1 |
| gnu | binutils | >= 0 < 2.34-6ubuntu1.10 | 2.34-6ubuntu1.10 |
| gnu | binutils | >= 0 < 2.38-4ubuntu2.7 | 2.38-4ubuntu2.7 |
| gnu | binutils | >= 0 < 2.42-4ubuntu2.4 | 2.42-4ubuntu2.4 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
GNU binutils vulnerabilities
vendor_ubuntu·2025-02-26·CVSS 5.5
CVE-2025-0840 [MEDIUM] GNU binutils vulnerabilities
Title: GNU binutils vulnerabilities
Summary: Several security issues were fixed in GNU binutils.
It was discovered that GNU binutils in nm tool is affected by an
incorrect access control. An attacker could possibly use this issue
to cause a crash. This issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04
LTS, and Ubuntu 24.10. (CVE-2024-57360)
It was discovered that GNU binutils incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a crash or execute
arbitrary code. (CVE-2025-0840)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
binutils: nm: potential segmentation fault when displaying symbols without version info
vendor_redhat·2025-01-21·CVSS 5.5
CVE-2024-57360 [MEDIUM] CWE-754 binutils: nm: potential segmentation fault when displaying symbols without version info
binutils: nm: potential segmentation fault when displaying symbols without version info
https://www.gnu.org/software/binutils/ nm >=2.43 is affected by: Incorrect Access Control. The type of exploitation is: local. The component is: `nm --without-symbol-version` function.
A flaw was found in the nm utility of binutils. A local user who specifies the `--without-symbol-versions` option on a specially crafted ELF file can trigger a segmentation fault condition. This may lead to an application crash or other undefined behavior.
Package: binutils (Red Hat Enterprise Linux 10) - Fix deferred
Package: mingw-binutils (Red Hat Enterprise Linux 10) - Fix deferred
Package: binutils (Red Hat Enterprise Linux 6) - Fix deferred
Package: binutils (Red Hat Enterprise Linux 7) - Fix deferred
Package
Debian
CVE-2024-57360: binutils - https://www.gnu.org/software/binutils/ nm >=2.43 is affected by: Incorrect Acces...
vendor_debian·2024·CVSS 5.5
CVE-2024-57360 [MEDIUM] CVE-2024-57360: binutils - https://www.gnu.org/software/binutils/ nm >=2.43 is affected by: Incorrect Acces...
https://www.gnu.org/software/binutils/ nm >=2.43 is affected by: Incorrect Access Control. The type of exploitation is: local. The component is: `nm --without-symbol-version` function.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 2.43.50.20241221-1)
sid: resolved (fixed in 2.43.50.20241221-1)
trixie: resolved (fixed in 2.43.50.20241221-1)
OSV
binutils vulnerabilities
osv·2025-02-26·CVSS 5.5
CVE-2024-57360 [MEDIUM] binutils vulnerabilities
binutils vulnerabilities
It was discovered that GNU binutils in nm tool is affected by an
incorrect access control. An attacker could possibly use this issue
to cause a crash. This issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04
LTS, and Ubuntu 24.10. (CVE-2024-57360)
It was discovered that GNU binutils incorrectly handled certain inputs.
An attacker could possibly use this issue to cause a crash or execute
arbitrary code. (CVE-2025-0840)
GHSA
GHSA-cwjw-x748-4mm6: https://www
ghsa_unreviewed·2025-01-21
CVE-2024-57360 [HIGH] CWE-284 GHSA-cwjw-x748-4mm6: https://www
https://www.gnu.org/software/binutils/ nm >=2.43 is affected by: Incorrect Access Control. The type of exploitation is: local. The component is: `nm --without-symbol-version` function.
OSV
CVE-2024-57360: https://www
osv·2025-01-21·CVSS 5.5
CVE-2024-57360 [MEDIUM] CVE-2024-57360: https://www
https://www.gnu.org/software/binutils/ nm >=2.43 is affected by: Incorrect Access Control. The type of exploitation is: local. The component is: `nm --without-symbol-version` function.
No detection rules found.
No public exploits indexed.
2025-01-21
Published