Lucene search

K
mageiaGentoo FoundationMGASA-2022-0425
HistoryNov 13, 2022 - 5:25 a.m.

Updated binutils/gdb packages fix security vulnerability

2022-11-1305:25:20
Gentoo Foundation
advisories.mageia.org
34
binutils
gdb
security vulnerability
d-demangle
objcopy
heap buffer overflow
stack buffer overflow
libiberty
unix

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS

0.003

Percentile

70.5%

libiberty: Heap/stack buffer overflow in the dlang_lname function in d-demangle.c (CVE-2021-3826) binutils: heap-based buffer overflow in bfd_getl32() when called by strip_main() in objcopy.c via a crafted file (CVE-2022-38533)

OSVersionArchitecturePackageVersionFilename
Mageia8noarchbinutils< 2.36.1-1.5binutils-2.36.1-1.5.mga8
Mageia8noarchgdb< 10.1-5.1gdb-10.1-5.1.mga8

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS

0.003

Percentile

70.5%