CVE-2018-7569: Integer Overflow
A flaw was found in the readattributevalue function in dwarf2.c file in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils up to version 2.30, when compiled in 32bit mode. This allows attackers to cause a denial of service (integer wraparound and application crash) via an ELF file with a corrupt DWARF FORM block.
References: https://sourceware.org/bugzilla/showbug.cgi?id=22895
Patch: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=12c963421d045a127c413a0722062b9932c50aa9
Other sources
dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to cause a denial of service (integer underflow or overflow, and application crash) via an ELF file with a corrupt DWARF FORM block, as demonstrated by nm.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/binutilsto a version that resolves this vulnerability.Fixed in 2.35.2-2Fixed in 2.40-2Fixed in 2.44-3
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2018-7569.
What is the severity of CVE-2018-7569?
The severity of CVE-2018-7569 is low.
What is the affected software?
The affected software is GNU Binutils version 2.30.
How does CVE-2018-7569 impact the affected software?
CVE-2018-7569 allows remote attackers to cause a denial of service (integer underflow or overflow, and application crash) via a corrupt ELF file.
How can I fix CVE-2018-7569?
To fix CVE-2018-7569, update to the latest version of GNU Binutils or apply the available patches.