Null pointer dereference in Binutils - CVE-2018-12697

 

Null pointer dereference in Binutils - CVE-2018-12697

Published: June 26, 2018


Vulnerability identifier: #VU13473
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-12697
CWE-ID: CWE-476
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to cause DoS condition on the target system.

The vulnerability exists due to NULL pointer dereference in the work_stuff_copy_to_from function, as defined in the cplus-dem.csource code file in the GNU libiberty library. A local attacker can execute the objdump command, trigger NULL pointer dereference condition and cause the service to crash.


Affected software

Binutils
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
binutils (Red Hat package)
Data Computing Appliance (DCA)

How to mitigate CVE-2018-12697

Cybersecurity Help is currently unaware of any solutions addressing the vulnerability.

binutils (Red Hat package) - update to 2.27-41.base.el7
Data Computing Appliance (DCA) - update to 4.3.0.0

External References

Related Security Bulletins