Lucene search

K
f5F5F5:K62553631
HistoryJul 23, 2018 - 12:00 a.m.

K62553631 : Binutils vulnerabilities CVE-2018-7570, CVE-2018-9996, and CVE-2018-10372

2018-07-2300:00:00
my.f5.com
8

6.1 Medium

AI Score

Confidence

High

0.005 Low

EPSS

Percentile

76.1%

Security Advisory Description

The assign_file_positions_for_non_load_sections function in elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an ELF file with a RELRO segment that lacks a matching LOAD segment, as demonstrated by objcopy.

An issue was discovered in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30. Stack Exhaustion occurs in the C++ demangling functions provided by libiberty, and there are recursive stack frames: demangle_template_value_parm, demangle_integral_value, and demangle_expression.

process_cu_tu_index in dwarf.c in GNU Binutils 2.30 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted binary file, as demonstrated by readelf.

Impact

There is no impact; F5 products are not affected by this vulnerability.