Allocation of Resources Without Limits or Throttling
Affecting binutils package, versions *
Report new vulnerabilities
Do your applications use this vulnerable package?
Test your applications
Overview
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is an attempted excessive memory allocation in _bfd_elf_slurp_version_tables in elf.c.
References
CVSS Score
5.5
low severity
-
Attack VectorLocal
-
Attack ComplexityLow
-
Privileges RequiredNone
-
User InteractionRequired
-
ScopeUnchanged
-
ConfidentialityNone
-
IntegrityNone
-
AvailabilityHigh
- CVE
- CVE-2019-9073
- CWE
- CWE-770
- Snyk ID
- SNYK-DEBIAN9-BINUTILS-337980
- Disclosed
- 24 Feb, 2019
- Published
- 24 Feb, 2019