Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:26893
HistorySep 21, 2020 - 6:24 a.m.

Denial Of Service (DoS)

2020-09-2106:24:17
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11

0.004 Low

EPSS

Percentile

73.5%

binutils:bionic is vulnerable to denial of service. A heap-based buffer over-read issue was discovered in the function sec_merge_hash_lookup in merge.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31, because _bfd_add_merge_section mishandles section merges when size is not a multiple of entsize. A specially crafted ELF allows remote attackers to cause a denial of service, as demonstrated by ld.