REDHAT-BUG-2443828: Buffer Overflow
Summary: A separate heap-based buffer overflow (Out-of-Bounds Read) was found in GNU Binutils (bfd linker) in bfd/xcofflink.c. This issue occurs in xcofflinkaddsymbols (approx line 2282) where rsymndx is used to index symbol hashes without sufficient bounds checking. Requirements to exploit: An attacker needs to trick a user into running the ld linker against a specially crafted malicious XCOFF object file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2443828?
The severity of REDHAT-BUG-2443828 is categorized as high due to the potential for a heap-based buffer overflow exploit.
How do I fix REDHAT-BUG-2443828?
To fix REDHAT-BUG-2443828, update your GNU Binutils to the latest patched version provided by your vendor.
What is the impact of REDHAT-BUG-2443828?
The impact of REDHAT-BUG-2443828 can lead to application crashes or exploitation through crafted inputs, compromising system stability.
Who is affected by REDHAT-BUG-2443828?
Users and systems running vulnerable versions of GNU Binutils are affected by REDHAT-BUG-2443828.
What components are involved in REDHAT-BUG-2443828?
The components involved in REDHAT-BUG-2443828 include the 'bfd' linker in the GNU Binutils package.