First published: Fri Feb 09 2018(Updated: )
The elf_parse_notes function in elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to cause a denial of service (out-of-bounds read and segmentation violation) via a note with a large alignment.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ubuntu/binutils | =2.30 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-6872 has been classified as a high severity vulnerability due to the potential for remote denial of service.
The best way to mitigate CVE-2018-6872 is to upgrade to a patched version of GNU Binutils beyond 2.30.
CVE-2018-6872 can be exploited by remote attackers to cause a denial of service through out-of-bounds read and segmentation violation.
CVE-2018-6872 affects GNU Binutils version 2.30 and earlier.
Yes, if you are using GNU Binutils 2.30 or earlier, you should be concerned as CVE-2018-6872 presents a denial of service risk.