First published: Tue Aug 22 2023(Updated: )
GNU Binutils before 2.40 was discovered to contain an excessive memory consumption vulnerability via the function bfd_dwarf2_find_nearest_line_with_alt at dwarf2.c. The attacker could supply a crafted ELF file and cause a DNS attack.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNU Binutils | <2.40 | |
Fedoraproject Fedora | =37 | |
Fedoraproject Fedora | =38 | |
NetApp ONTAP Select Deploy administration utility |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-48064 is a vulnerability in GNU Binutils before version 2.40 that allows an attacker to cause excessive memory consumption.
CVE-2022-48064 affects GNU Binutils before version 2.40 by allowing an attacker to supply a crafted ELF file and cause a DNS attack.
CVE-2022-48064 has a severity rating of medium with a severity value of 5.5.
To fix CVE-2022-48064, update GNU Binutils to version 2.40 or later.
You can find more information about CVE-2022-48064 at the following references: [Reference 1](https://sourceware.org/bugzilla/show_bug.cgi?id=29922) and [Reference 2](https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=8f2c64de86bc3d7556121fe296dd679000283931).