First published: Tue Aug 22 2023(Updated: )
Heap buffer overflow vulnerability in binutils readelf before 2.40 via function find_section_in_set in file readelf.c.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNU Binutils | <2.40 | |
debian/binutils | <=2.35.2-2 | 2.40-2 2.43.50.20250108-1 |
https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=28750e3b967da2207d51cbce9fc8be262817ee59
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this heap buffer overflow vulnerability is CVE-2022-44840.
The GNU Binutils package before version 2.40 and certain versions of the binutils package in Debian and Ubuntu are affected by this vulnerability.
The severity of CVE-2022-44840 is high with a CVSS score of 7.8.
To fix this vulnerability in GNU Binutils, you need to update to version 2.40 or later.
To fix this vulnerability in Debian, update the binutils package to version 2.40-2 or 2.41-5. For Ubuntu, update the binutils package to the respective versions specified in the Ubuntu security advisories.