5.5
CVSSv3

CVE-2018-18605

Published: 23/10/2018 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

A heap-based buffer over-read issue exists in the function sec_merge_hash_lookup in merge.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31, because _bfd_add_merge_section mishandles section merges when size is not a multiple of entsize. A specially crafted ELF allows remote malicious users to cause a denial of service, as demonstrated by ld.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gnu binutils 2.31

debian debian linux 8.0

debian debian linux 7.0

debian debian linux 9.0

netapp data ontap -

Vendor Advisories

Several security issues were fixed in GNU binutils ...
A heap-based buffer over-read issue was discovered in the function sec_merge_hash_lookup in mergec in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 231, because _bfd_add_merge_section mishandles section merges when size is not a multiple of entsize A specially crafted ELF allows remote attackers to cause a ...