CVE-2018-10372: Medium severity GNU binutils vulnerability
GNU Binutils through version 2.30 has a heap-based buffer over-read vulnerability in dwarf.c:processcutuindex(). An attacker could exploit this to crash the readelf application by providing a binary file.
Upstream Issue:
https://sourceware.org/bugzilla/showbug.cgi?id=23064
Upstream Patch:
https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=6aea08d9f3e3d6475a65454da488a0c51f5dc97d
Other sources
processcutuindex in dwarf.c in GNU Binutils 2.30 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted binary file, as demonstrated by readelf.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2018-10372?
CVE-2018-10372 is a vulnerability in GNU Binutils 2.30 that allows remote attackers to cause a denial of service through a crafted binary file.
How can CVE-2018-10372 be exploited?
CVE-2018-10372 can be exploited by sending a specially crafted binary file to the affected system.
What is the severity of CVE-2018-10372?
CVE-2018-10372 has a low severity level.
Which versions of GNU Binutils are affected by CVE-2018-10372?
GNU Binutils 2.30 is affected by CVE-2018-10372.
Is there a remedy for CVE-2018-10372?
Yes, the remedy for CVE-2018-10372 is to upgrade to binutils version 2.30.90.20180627-1 or higher.