Do your applications use this vulnerable package?
Test your applications
Overview
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. An invalid memory access exists in bfd_zalloc in opncls.c. Attackers could leverage this vulnerability to cause a denial of service (application crash) via a crafted ELF file.
References
CVSS Score
5.5
low severity
-
Attack VectorLocal
-
Attack ComplexityLow
-
Privileges RequiredNone
-
User InteractionRequired
-
ScopeUnchanged
-
ConfidentialityNone
-
IntegrityNone
-
AvailabilityHigh
- CVE
- CVE-2018-17359
- CWE
- CWE-119
- Snyk ID
- SNYK-DEBIAN9-BINUTILS-403864
- Disclosed
- 23 Sep, 2018
- Published
- 23 Sep, 2018