Do your applications use this vulnerable package?
Test your applications
Overview
dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to cause a denial of service (integer underflow or overflow, and application crash) via an ELF file with a corrupt DWARF FORM block, as demonstrated by nm.
References
CVSS Score
5.5
medium severity
-
Attack VectorLocal
-
Attack ComplexityLow
-
Privileges RequiredNone
-
User InteractionRequired
-
ScopeUnchanged
-
ConfidentialityNone
-
IntegrityNone
-
AvailabilityHigh
- CVE
- CVE-2018-7569
- CWE
- CWE-190 CWE-191
- Snyk ID
- SNYK-DEBIAN9-BINUTILS-403980
- Disclosed
- 28 Feb, 2018
- Published
- 28 Feb, 2018