Lucene search

K
osvGoogleOSV:USN-5341-1
HistoryMar 22, 2022 - 12:12 p.m.

binutils vulnerabilities

2022-03-2212:12:25
Google
osv.dev
10
memory allocation
relocs
corrupt file
denial of service
cve-2017-17122
dwarf debug sections
memory consumption
stabs debugging information
bounds checking
arbitrary code execution
cve-2021-3487
cve-2021-45078
gnu binutils
software

AI Score

7.6

Confidence

High

EPSS

0.003

Percentile

70.8%

It was discovered that GNU binutils incorrectly handled checks for memory
allocation when parsing relocs in a corrupt file. An attacker could possibly
use this issue to cause a denial of service. (CVE-2017-17122)

It was discovered that GNU binutils incorrectly handled certain corrupt DWARF
debug sections. An attacker could possibly use this issue to cause GNU
binutils to consume memory, resulting in a denial of service. (CVE-2021-3487)

It was discovered that GNU binutils incorrectly performed bounds checking
operations when parsing stabs debugging information. An attacker could
possibly use this issue to cause a denial of service or execute arbitrary
code. (CVE-2021-45078)