Allocation of Resources Without Limits or Throttling
Affecting binutils package, versions *
Report new vulnerabilities
Do your applications use this vulnerable package?
Test your applications
Overview
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is an attempted excessive memory allocation in setup_group in elf.c.
References
CVSS Score
5.5
medium severity
-
Attack VectorLocal
-
Attack ComplexityLow
-
Privileges RequiredNone
-
User InteractionRequired
-
ScopeUnchanged
-
ConfidentialityNone
-
IntegrityNone
-
AvailabilityHigh
- CVE
- CVE-2019-9072
- CWE
- CWE-770
- Snyk ID
- SNYK-DEBIAN10-BINUTILS-338006
- Disclosed
- 24 Feb, 2019
- Published
- 24 Feb, 2019