REDHAT-BUG-1573356: Low severity GNU binutils vulnerability
GNU Binutils through version 2.30 has a heap-based buffer over-read vulnerability in dwarf.c:processcutuindex(). An attacker could exploit this to crash the readelf application by providing a binary file.
Upstream Issue:
https://sourceware.org/bugzilla/showbug.cgi?id=23064
Upstream Patch:
https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=6aea08d9f3e3d6475a65454da488a0c51f5dc97d
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1573356?
The severity of REDHAT-BUG-1573356 is high due to the potential for an attacker to crash the readelf application.
How do I fix REDHAT-BUG-1573356?
To fix REDHAT-BUG-1573356, update GNU Binutils to a version newer than 2.30.
What type of vulnerability is REDHAT-BUG-1573356?
REDHAT-BUG-1573356 is classified as a heap-based buffer over-read vulnerability.
Can REDHAT-BUG-1573356 be exploited remotely?
Yes, REDHAT-BUG-1573356 can potentially be exploited remotely by providing a malicious binary file.
Which versions of GNU Binutils are affected by REDHAT-BUG-1573356?
GNU Binutils versions up to and including 2.30 are affected by REDHAT-BUG-1573356.