CVE-2018-6872: Medium severity GNU binutils vulnerability
The elfparsenotes function in elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to cause a denial of service (out-of-bounds read and segmentation violation) via a note with a large alignment.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-6872?
CVE-2018-6872 has been classified as a high severity vulnerability due to the potential for remote denial of service.
How do I fix CVE-2018-6872?
The best way to mitigate CVE-2018-6872 is to upgrade to a patched version of GNU Binutils beyond 2.30.
What type of attack is associated with CVE-2018-6872?
CVE-2018-6872 can be exploited by remote attackers to cause a denial of service through out-of-bounds read and segmentation violation.
Which software is affected by CVE-2018-6872?
CVE-2018-6872 affects GNU Binutils version 2.30 and earlier.
Should I be concerned about CVE-2018-6872 on my server?
Yes, if you are using GNU Binutils 2.30 or earlier, you should be concerned as CVE-2018-6872 presents a denial of service risk.