Improper input validation in Binutils - CVE-2018-7208

 

Improper input validation in Binutils - CVE-2018-7208

Published: March 5, 2018


Vulnerability identifier: #VU10837
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-7208
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The weakness exists in the coff_pointerize_aux function in the coffgen.c source code due to insufficient validation of an index. A remote attacker can create a specially crafted COFF file, trick the victim into opening it, trigger a segmentation fault and cause the service to crash.

Affected software

Binutils
Gentoo Linux
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Software Development Kit 12
binutils (Alpine package)
gdb
gdbserver-32bit
gdbserver-debuginfo-32bit
gdb-debuginfo-32bit
gdbserver-debuginfo
gdbserver
gdb-debugsource
gdb-debuginfo
EMC Cloud Tiering Appliance

How to mitigate CVE-2018-7208

Install update from vendor's website.

binutils (Alpine package) - update to 2.30-r2
gdb - addressed in versions 12.1-2.20.1, 13.2-2.23.1
gdbserver-32bit - addressed in versions 12.1-2.20.1, 13.2-2.23.1
gdbserver-debuginfo-32bit - addressed in versions 12.1-2.20.1, 13.2-2.23.1
gdb-debuginfo-32bit - addressed in versions 12.1-2.20.1, 13.2-2.23.1
gdbserver-debuginfo - addressed in versions 12.1-2.20.1, 13.2-2.23.1
gdbserver - addressed in versions 12.1-2.20.1, 13.2-2.23.1
gdb-debugsource - addressed in versions 12.1-2.20.1, 13.2-2.23.1
gdb-debuginfo - addressed in versions 12.1-2.20.1, 13.2-2.23.1
EMC Cloud Tiering Appliance - update to 13.2.0.2.29

External References

Related Security Bulletins