Do your applications use this vulnerable package?
Test your applications
Overview
In GNU Binutils 2.31.1, there is a use-after-free in the error function in elfcomm.c when called from the process_archive function in readelf.c via a crafted ELF file.
References
CVSS Score
5.5
low severity
-
Attack VectorLocal
-
Attack ComplexityLow
-
Privileges RequiredNone
-
User InteractionRequired
-
ScopeUnchanged
-
ConfidentialityNone
-
IntegrityNone
-
AvailabilityHigh
- CVE
- CVE-2018-20623
- CWE
- CWE-416
- Snyk ID
- SNYK-DEBIAN10-BINUTILS-403909
- Disclosed
- 31 Dec, 2018
- Published
- 31 Dec, 2018