7.5
CVSSv3

CVE-2021-46174

Published: 22/08/2023 Updated: 25/08/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

A memory consumption issue in get_data function in binutils/nm.c in GNU nm prior to 2.34 allows malicious users to cause a denial of service via crafted command. (CVE-2020-19724) Heap-based Buffer Overflow in function bfd_getl32 in Binutils objdump 3.37. (CVE-2021-46174) An issue exists in Binutils readelf 2.38.50, reachable assertion failure in function display_debug_names allows malicious users to cause a denial of service. (CVE-2022-35205) An issue exists function stab_demangle_v3_arg in stabs.c in Binutils 2.34 thru 2.38, allows malicious users to cause a denial of service due to memory leaks. (CVE-2022-47007) An issue exists function make_tempdir, and make_tempname in bucomm.c in Binutils 2.34 thru 2.38, allows malicious users to cause a denial of service due to memory leaks. (CVE-2022-47008) An issue exists function pr_function_type in prdbg.c in Binutils 2.34 thru 2.38, allows malicious users to cause a denial of service due to memory leaks. (CVE-2022-47010) GNU Binutils prior to 2.40 exists to contain an excessive memory consumption vulnerability via the function bfd_dwarf2_find_nearest_line_with_alt at dwarf2.c. The attacker could supply a crafted ELF file and cause a DNS attack. (CVE-2022-48064) Potential heap based buffer overflow found in _bfd_elf_slurp_version_tables() in bfd/elf.c. (CVE-2023-1972)

Vulnerable Product Search on Vulmon Subscribe to Product

gnu binutils

Vendor Advisories

A memory consumption issue in get_data function in binutils/nmc in GNU nm before 234 allows attackers to cause a denial of service via crafted command (CVE-2020-19724) Heap-based Buffer Overflow in function bfd_getl32 in Binutils objdump 337 (CVE-2021-46174) An issue was discovered in Binutils readelf 23850, reachable assertion failure in fu ...