CVE-2022-48063: Medium severity binutils vulnerability
GNU Binutils before 2.40 was discovered to contain an excessive memory consumption vulnerability via the function loadseparatedebugfiles at dwarf2.c. The attacker could supply a crafted ELF file and cause a DNS attack.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-48063?
CVE-2022-48063 is a vulnerability in GNU Binutils before version 2.40 that allows for excessive memory consumption and can be exploited through a crafted ELF file, leading to a DNS attack.
How severe is CVE-2022-48063?
CVE-2022-48063 has a severity level of 5.5, which is considered medium.
What is the affected software for CVE-2022-48063?
The affected software for CVE-2022-48063 is GNU Binutils before version 2.40.
How can I fix CVE-2022-48063?
To fix CVE-2022-48063, you should update GNU Binutils to version 2.40 or later.
Where can I find more information about CVE-2022-48063?
You can find more information about CVE-2022-48063 at the following references: [Link 1](https://sourceware.org/bugzilla/show_bug.cgi?id=29924), [Link 2](https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=75393a2d54bcc40053e5262a3de9d70c5ebfbbfd), [Link 3](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-48063).