CVE-2018-1000876: Integer Overflow
An integer overflow was found in objdump, bfdgetdynamicrelocupperbound and bfdcanonicalizedynamicreloc functions of binutils. A local attacker could use this to crash the application or potentially achieve code execution.
Upstream issue:
https://sourceware.org/bugzilla/showbug.cgi?id=23994
Upstream patch:
https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=3a551c7a1b80fca579461774860574eabfd7f18f
Other sources
binutils version 2.32 and earlier contains a Integer Overflow vulnerability in objdump, bfdgetdynamicrelocupperbound,bfdcanonicalizedynamicreloc that can result in Integer overflow trigger heap overflow. Successful exploitation allows execution of arbitrary code.. This attack appear to be exploitable via Local. This vulnerability appears to have been fixed in after commit 3a551c7a1b80fca579461774860574eabfd7f18f.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/binutilsto a version that resolves this vulnerability.Fixed in 0:2.27-41.base.el7 - Upgrade
Upgrade
debian/binutilsto a version that resolves this vulnerability.Fixed in 2.35.2-2Fixed in 2.40-2Fixed in 2.44-3 - Upgrade
Upgrade
binutilsto a version that resolves this vulnerability.Patch 3a551c7a1b80fca579461774860574eabfd7f18f
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2018-1000876?
CVE-2018-1000876 is a vulnerability found in binutils version 2.32 and earlier that allows an attacker to trigger a heap overflow, potentially leading to the execution of arbitrary code.
What is the severity of CVE-2018-1000876?
The severity of CVE-2018-1000876 is rated as high with a CVSS score of 7.8.
Which software versions are affected by CVE-2018-1000876?
CVE-2018-1000876 affects binutils version 2.32 and earlier.
How can I fix the CVE-2018-1000876 vulnerability?
To fix the CVE-2018-1000876 vulnerability, you should update binutils to a version higher than 2.32.
Where can I find more information about CVE-2018-1000876?
You can find more information about CVE-2018-1000876 at the following references: [Link 1](https://sourceware.org/bugzilla/show_bug.cgi?id=23994), [Link 2](https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=3a551c7a1b80fca579461774860574eabfd7f18f), [Link 3](http://www.securityfocus.com/bid/106304).