First published: Sun Dec 16 2018(Updated: )
An integer overflow was found in objdump, bfd_get_dynamic_reloc_upper_bound and bfd_canonicalize_dynamic_reloc functions of binutils. A local attacker could use this to crash the application or potentially achieve code execution. Upstream issue: <a href="https://sourceware.org/bugzilla/show_bug.cgi?id=23994">https://sourceware.org/bugzilla/show_bug.cgi?id=23994</a> Upstream patch: <a href="https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=3a551c7a1b80fca579461774860574eabfd7f18f">https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=3a551c7a1b80fca579461774860574eabfd7f18f</a>
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/binutils | <0:2.27-41.base.el7 | 0:2.27-41.base.el7 |
GNU Binutils | <2.32 | |
Canonical Ubuntu Linux | =18.04 | |
Redhat Enterprise Linux Desktop | =7.0 | |
Redhat Enterprise Linux Server | =7.0 | |
Redhat Enterprise Linux Workstation | =7.0 | |
debian/binutils | 2.35.2-2 2.40-2 2.43.50.20241215-1 2.43.50.20241221-1 |
https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=3a551c7a1b80fca579461774860574eabfd7f18f
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1000876 is a vulnerability found in binutils version 2.32 and earlier that allows an attacker to trigger a heap overflow, potentially leading to the execution of arbitrary code.
The severity of CVE-2018-1000876 is rated as high with a CVSS score of 7.8.
CVE-2018-1000876 affects binutils version 2.32 and earlier.
To fix the CVE-2018-1000876 vulnerability, you should update binutils to a version higher than 2.32.
You can find more information about CVE-2018-1000876 at the following references: [Link 1](https://sourceware.org/bugzilla/show_bug.cgi?id=23994), [Link 2](https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=3a551c7a1b80fca579461774860574eabfd7f18f), [Link 3](http://www.securityfocus.com/bid/106304).