CVE-2018-7568
MEDIUMGNU Binutils - Integer Overflow
Title source: ruleDescription
The parse_die function in dwarf1.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to cause a denial of service (integer overflow and application crash) via an ELF file with corrupt dwarf1 debug information, as demonstrated by nm.
References (6)
Scores
CVSS v3
5.5
EPSS
0.0017
EPSS Percentile
38.3%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Classification
CWE
CWE-190
Status
published
Affected Products (4)
gnu/binutils
redhat/enterprise_linux_desktop
redhat/enterprise_linux_server
redhat/enterprise_linux_workstation
Timeline
Published
Feb 28, 2018
Tracked Since
Feb 18, 2026