Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:43635
HistoryOct 09, 2023 - 1:17 p.m.

Out-of-Bounds Read

2023-10-0913:17:55
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12
binutils
out-of-bounds read
parse_module
remote attackers
arbitrary code
malicious object file
bfd/vms-alpha.c

7.1 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H

0.0005 Low

EPSS

Percentile

18.9%

binutils is vulnerable to Out-of-Bounds Reads. The vulnerability allows remote attackers to execute arbitrary code on the system by crafting a malicious object file due to the vulnerable logic in the parse_module function of bfd/vms-alpha.c.

7.1 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H

0.0005 Low

EPSS

Percentile

18.9%