NA

CVE-2023-1972

Published: 17/05/2023 Updated: 30/09/2023
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

A memory consumption issue in get_data function in binutils/nm.c in GNU nm prior to 2.34 allows malicious users to cause a denial of service via crafted command. (CVE-2020-19724) Heap-based Buffer Overflow in function bfd_getl32 in Binutils objdump 3.37. (CVE-2021-46174) An issue exists in Binutils readelf 2.38.50, reachable assertion failure in function display_debug_names allows malicious users to cause a denial of service. (CVE-2022-35205) An issue exists function stab_demangle_v3_arg in stabs.c in Binutils 2.34 thru 2.38, allows malicious users to cause a denial of service due to memory leaks. (CVE-2022-47007) An issue exists function make_tempdir, and make_tempname in bucomm.c in Binutils 2.34 thru 2.38, allows malicious users to cause a denial of service due to memory leaks. (CVE-2022-47008) An issue exists function pr_function_type in prdbg.c in Binutils 2.34 thru 2.38, allows malicious users to cause a denial of service due to memory leaks. (CVE-2022-47010) GNU Binutils prior to 2.40 exists to contain an excessive memory consumption vulnerability via the function bfd_dwarf2_find_nearest_line_with_alt at dwarf2.c. The attacker could supply a crafted ELF file and cause a DNS attack. (CVE-2022-48064) Potential heap based buffer overflow found in _bfd_elf_slurp_version_tables() in bfd/elf.c. (CVE-2023-1972)

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gnu binutils

Vendor Advisories

A memory consumption issue in get_data function in binutils/nmc in GNU nm before 234 allows attackers to cause a denial of service via crafted command (CVE-2020-19724) Heap-based Buffer Overflow in function bfd_getl32 in Binutils objdump 337 (CVE-2021-46174) An issue was discovered in Binutils readelf 23850, reachable assertion failure in fu ...
Description<!----> This CVE is under investigation by Red Hat Product Security ...