CVE-2018-6759
MEDIUMGNU Binutils - Improper Input Validation
Title source: ruleDescription
The bfd_get_debug_link_info_1 function in opncls.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, has an unchecked strnlen operation. Remote attackers could leverage this vulnerability to cause a denial of service (segmentation fault) via a crafted ELF file.
References (5)
Scores
CVSS v3
5.5
EPSS
0.0024
EPSS Percentile
46.5%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Classification
CWE
CWE-20
Status
published
Affected Products (1)
gnu/binutils
Timeline
Published
Feb 06, 2018
Tracked Since
Feb 18, 2026