Allocation of Resources Without Limits or Throttling
Affecting binutils package, versions *
Report new vulnerabilities
Do your applications use this vulnerable package?
Test your applications
Overview
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted ELF file, as demonstrated by _bfd_elf_parse_attributes in elf-attrs.c and bfd_malloc in libbfd.c. This can occur during execution of nm.
References
CVSS Score
5.5
low severity
-
Attack VectorLocal
-
Attack ComplexityLow
-
Privileges RequiredNone
-
User InteractionRequired
-
ScopeUnchanged
-
ConfidentialityNone
-
IntegrityNone
-
AvailabilityHigh
- CVE
- CVE-2018-13033
- CWE
- CWE-770
- Snyk ID
- SNYK-DEBIAN9-BINUTILS-403924
- Disclosed
- 01 Jul, 2018
- Published
- 11 Jul, 2018