First published: Mon Feb 06 2023(Updated: )
A flaw was found in Binutils. The field `the_bfd` of `asymbol`struct is uninitialized in the `bfd_mach_o_get_synthetic_symtab` function, which may lead to an application crash and local denial of service.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
GNU Binutils | =2.40 |
https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=d12f8998d2d086f0a6606589e5aedb7147e6f2f1
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this flaw is CVE-2023-25588.
The severity rating for CVE-2023-25588 is medium with a value of 5.5.
This vulnerability may lead to an application crash and local denial of service in the affected software.
The affected version of GNU Binutils is 2.40.
You can find more information about this vulnerability at the following references: [Red Hat Security Advisory](https://access.redhat.com/security/cve/CVE-2023-25588), [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=2167505), [Sourceware Bugzilla](https://sourceware.org/bugzilla/show_bug.cgi?id=29677).