Buffer overflow in Binutils - CVE-2024-57360

 

Buffer overflow in Binutils - CVE-2024-57360

Published: February 12, 2025


Vulnerability identifier: #VU103886
CSH Severity: High
CVSS v4: 7.5 [CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-57360
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error when handling files within the nm binary. A remote attacker can pass specially crafted input to the application, trigger memory corruption and execute arbitrary code on the target system.



Affected software

Binutils
Ubuntu
openEuler
Anolis OS
binutils (Ubuntu package)
binutils-multiarch (Ubuntu package)
binutils-help
binutils
binutils-debuginfo
binutils-debugsource
binutils-devel
binutils-gold
binutils-doc

How to mitigate CVE-2024-57360

Install updates from vendor's website.

Binutils - update to 2.44
binutils (Ubuntu package) - addressed in versions 2.34-6ubuntu1.10, 2.38-4ubuntu2.7, 2.42-4ubuntu2.4, 2.43.1-4ubuntu1.1
binutils-multiarch (Ubuntu package) - addressed in versions 2.34-6ubuntu1.10, 2.38-4ubuntu2.7, 2.42-4ubuntu2.4, 2.43.1-4ubuntu1.1
binutils-help - addressed in versions 2.37-28, 2.37-30, 2.41-10, 2.41-14
binutils - addressed in versions 2.37-28, 2.37-30, 2.41-10, 2.41-14
binutils-debuginfo - addressed in versions 2.37-28, 2.37-30, 2.41-10, 2.41-14
binutils-debugsource - addressed in versions 2.37-28, 2.37-30, 2.41-10, 2.41-14
binutils-devel - addressed in versions 2.37-28, 2.37-30, 2.41-10, 2.41-14
binutils - update to 2.41-10
binutils-devel - update to 2.41-10
binutils-gold - update to 2.41-10
binutils-doc - update to 2.41-10

External References

Related Security Bulletins