CVE-2018-6759: Input Validation
Last updated 24 July 2024
Other sources
The bfdgetdebuglinkinfo1 function in opncls.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, has an unchecked strnlen operation. Remote attackers could leverage this vulnerability to cause a denial of service (segmentation fault) via a crafted ELF file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/binutilsto a version that resolves this vulnerability.Fixed in 2.35.2-2Fixed in 2.40-2Fixed in 2.44-3
Event History
Frequently Asked Questions
What is CVE-2018-6759?
CVE-2018-6759 is a vulnerability in the Binary File Descriptor (BFD) library that could allow remote attackers to cause a denial of service (segmentation fault) via a crafted ELF file.
Which software is affected by CVE-2018-6759?
The Binutils package versions 2.26.1-1ubuntu1~16.04.8+ to 2.31 are affected by CVE-2018-6759.
How can I fix CVE-2018-6759 on Ubuntu Xenial (16.04)?
To fix CVE-2018-6759 on Ubuntu Xenial (16.04), you need to update the Binutils package to version 2.31 or later.
How can I fix CVE-2018-6759 on Debian?
To fix CVE-2018-6759 on Debian, you need to update the Binutils package to version 2.31.1-16, 2.35.2-2, 2.40-2, or 2.41-5.
Where can I find more information about CVE-2018-6759?
You can find more information about CVE-2018-6759 at the following references: [Sourceware](https://sourceware.org/bugzilla/show_bug.cgi?id=22794), [SecurityFocus](http://www.securityfocus.com/bid/103030), [Gentoo](https://security.gentoo.org/glsa/201811-17)