REDHAT-BUG-1573365: Null Pointer Dereference
GNU Binutils through version 2.30 is vulnerable to a NULL pointer dereference in dwarf2.c:concatfilename(). An attacker could exploit this to crash the nm-new application by providing a binary file.
Upstream Issue:
https://sourceware.org/bugzilla/showbug.cgi?id=23065
Upstream Patch:
https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=6327533b1fd29fa86f6bf34e61c332c010e3c689
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1573365?
The severity of REDHAT-BUG-1573365 is considered high due to its potential to crash applications.
How do I fix REDHAT-BUG-1573365?
To fix REDHAT-BUG-1573365, update GNU Binutils to a version higher than 2.30.
What are the symptoms of REDHAT-BUG-1573365?
The symptoms of REDHAT-BUG-1573365 include the nm-new application crashing when processing a vulnerable binary file.
Can REDHAT-BUG-1573365 be exploited remotely?
REDHAT-BUG-1573365 can potentially be exploited by an attacker providing a specially crafted binary file.
Which versions of GNU Binutils are affected by REDHAT-BUG-1573365?
GNU Binutils versions up to and including 2.30 are affected by REDHAT-BUG-1573365.