Heap-based buffer overflow in Binutils - CVE-2018-12699
Published: June 25, 2018 / Updated: June 26, 2018
Vulnerability details
The vulnerability allows a local attacker to cause DoS condition on the target system.
The vulnerability exists due to heap-based buffer overflow in the finish_stab function, as defined in the stabs.c source code file. A local attacker can execute the objdump command, trigger memory corruption and cause the service to crash.
Affected software
IBM Qradar SIEM
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
openEuler
IBM Cloud Pak for Security
Red Hat OpenShift Dev Spaces
OpenShift Logging
binutils (Red Hat package)
binutils
binutils-devel
binutils-debugsource
binutils-help
binutils-debuginfo
Red Hat OpenShift Container Platform
Juniper Secure Analytics (JSA)
How to mitigate CVE-2018-12699
IBM Cloud Pak for Security - update to 1.11.2.0
binutils (Red Hat package) - update to 2.30-125.el8_10
binutils - update to 2.30-125.0.1
binutils-devel - update to 2.30-125.0.1
binutils - update to 2.34-18
binutils-devel - update to 2.34-18
binutils-debugsource - update to 2.34-18
binutils-help - update to 2.34-18
binutils-debuginfo - update to 2.34-18
Red Hat OpenShift Dev Spaces - update to 3.17.0
Red Hat OpenShift Container Platform - addressed in versions 4.14.42, 4.15.39
OpenShift Logging - update to 5.6.27
Juniper Secure Analytics (JSA) - update to 7.5.0 UP11 IF03
External References
Related Security Bulletins
- Denial of service in GNU Binutils
- openEuler update for binutils
- Red Hat Enterprise Linux 8 update for binutils
- Multiple vulnerabilities in Red Hat OpenShift Dev Spaces 3.17
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.15
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in OpenShift Logging 5.6
- Multiple vulnerabilities in IBM QRadar SIEM
- Anolis OS update for binutils
- Multiple vulnerabilities in IBM Cloud Pak for Security
- Juniper Secure Analytics update for third-party components