384
VMScore

CVE-2018-17360

Published: 23/09/2018 Updated: 31/10/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 384
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

An issue exists in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. a heap-based buffer over-read in bfd_getl32 in libbfd.c allows an malicious user to cause a denial of service through a crafted PE file. This vulnerability can be triggered by the executable objdump.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gnu binutils 2.31.1

Vendor Advisories

Several security issues were fixed in GNU binutils ...
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 231 a heap-based buffer over-read in bfd_getl32 in libbfdc allows an attacker to cause a denial of service through a crafted PE file This vulnerability can be triggered by the executable objdump ...