CVE-2018-10373: Null Pointer Dereference
concatfilename in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted binary file, as demonstrated by nm-new.
Other sources
GNU Binutils through version 2.30 is vulnerable to a NULL pointer dereference in dwarf2.c:concatfilename(). An attacker could exploit this to crash the nm-new application by providing a binary file.
Upstream Issue:
https://sourceware.org/bugzilla/showbug.cgi?id=23065
Upstream Patch:
https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=6327533b1fd29fa86f6bf34e61c332c010e3c689
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2018-10373.
What is the title of the vulnerability?
The title of the vulnerability is 'concat_filename in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd)'.
What is the severity level of CVE-2018-10373?
The severity level of CVE-2018-10373 is low.
What is the affected software?
The affected software is the Binary File Descriptor (BFD) library (aka libbfd) as distributed in GNU Binutils 2.30.
How can an attacker exploit CVE-2018-10373?
An attacker can exploit CVE-2018-10373 by sending a crafted binary file, which can cause a denial of service (NULL pointer dereference and application crash).