CVE-2018-7643: Integer Overflow
Last updated 24 July 2024
Other sources
The displaydebugranges function in dwarf.c in GNU Binutils 2.30 allows attackers to cause a denial of service (integer overflow and application crash) or possibly have unspecified other impact via a crafted ELF file, as demonstrated by objdump.
Upstream issue:
https://sourceware.org/bugzilla/showbug.cgi?id=22905
Upstream patch:
https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=d11ae95ea3403559f052903ab053f43ad7821e37
— Red Hat
The displaydebugranges function in dwarf.c in GNU Binutils 2.30 allows remote attackers to cause a denial of service (integer overflow and application crash) or possibly have unspecified other impact via a crafted ELF file, as demonstrated by objdump.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/binutilsto a version that resolves this vulnerability.Fixed in 2.35.2-2Fixed in 2.40-2Fixed in 2.44-3 - Upgrade
Upgrade
GNU Binutilsto a version that resolves this vulnerability.Fixed in 2.30 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch d11ae95ea3403559f052903ab053f43ad7821e37
Event History
Frequently Asked Questions
What is CVE-2018-7643?
CVE-2018-7643 is a vulnerability in GNU Binutils 2.30 that allows remote attackers to cause a denial of service or have unspecified other impact via a crafted ELF file.
How severe is CVE-2018-7643?
CVE-2018-7643 has a low severity level.
Which software versions are affected by CVE-2018-7643?
GNU Binutils 2.30-6 and 2.26.1-1ubuntu1~16.04.8+ are affected by CVE-2018-7643.
How can I fix CVE-2018-7643?
To fix CVE-2018-7643, update GNU Binutils to version 2.31.1-16, 2.35.2-2, 2.40-2, or 2.41-5.
Where can I find more information about CVE-2018-7643?
You can find more information about CVE-2018-7643 at the following references: [1] [2] [3].