Heap-based buffer overflow in Binutils - CVE-2018-20671

 

Heap-based buffer overflow in Binutils - CVE-2018-20671

Published: January 7, 2019


Vulnerability identifier: #VU16828
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-20671
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to integer overflow in load_specific_debug_section in objdump.c. A remote attacker can supply a specially crafted section size, trigger heap-based buffer overflow and perform a denial of service (DoS) attack.


Affected software

Binutils
Ubuntu
binutils (Ubuntu package)
binutils-multiarch (Ubuntu package)
VMware Tanzu Operations Manager
Isolation Segment
VMware Tanzu Application Service for VMs
Platform Automation Toolkit
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)

How to mitigate CVE-2018-20671

Install update from vendor's website.

binutils (Ubuntu package) - update to Ubuntu Pro (Infra-only)
binutils-multiarch (Ubuntu package) - update to Ubuntu Pro (Infra-only)
VMware Tanzu Operations Manager - update to 2.10.65
Isolation Segment - addressed in versions 3.0.19, 4.0.11
VMware Tanzu Application Service for VMs - addressed in versions 3.0.19, 4.0.11
Platform Automation Toolkit - addressed in versions 4.0.13, 4.1.13, 4.2.8, 4.3.5
Dell EMC Unity Operating Environment (OE) - update to 5.0.3.0.5.014
Dell EMC Unity VSA Operating Environment (OE) - update to 5.0.3.0.5.014

External References

Related Security Bulletins