[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250108

 
 

909

 
 

196064

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2-2024-2401 --- binutils

ID: oval:org.secpod.oval:def:1702013Date: (C)2024-02-07   (M)2024-04-17
Class: PATCHFamily: unix




A memory consumption issue in get_data function in binutils/nm.c in GNU nm before 2.34 allows attackers to cause a denial of service via crafted command. Heap-based Buffer Overflow in function bfd_getl32 in Binutils objdump 3.37. An issue was discovered in Binutils readelf 2.38.50, reachable assertion failure in function display_debug_names allows attackers to cause a denial of service. An issue was discovered function stab_demangle_v3_arg in stabs.c in Binutils 2.34 thru 2.38, allows attackers to cause a denial of service due to memory leaks. An issue was discovered function make_tempdir, and make_tempname in bucomm.c in Binutils 2.34 thru 2.38, allows attackers to cause a denial of service due to memory leaks. An issue was discovered function pr_function_type in prdbg.c in Binutils 2.34 thru 2.38, allows attackers to cause a denial of service due to memory leaks. GNU Binutils before 2.40 was discovered to contain an excessive memory consumption vulnerability via the function bfd_dwarf2_find_nearest_line_with_alt at dwarf2.c. The attacker could supply a crafted ELF file and cause a DNS attack. Potential heap based buffer overflow found in _bfd_elf_slurp_version_tables in bfd/elf.c

Platform:
Amazon Linux 2
Product:
binutils
Reference:
ALAS2-2024-2401
CVE-2020-19724
CVE-2021-46174
CVE-2022-35205
CVE-2022-47007
CVE-2022-47008
CVE-2022-47010
CVE-2022-48064
CVE-2023-1972
CVE    8
CVE-2023-1972
CVE-2020-19724
CVE-2022-35205
CVE-2022-47007
...
CPE    2
cpe:/o:amazon:linux:2
cpe:/a:sourceware:binutils

© SecPod Technologies