Memory leak in Binutils - CVE-2022-47008

 

Memory leak in Binutils - CVE-2022-47008

Published: December 5, 2023


Vulnerability identifier: #VU83860
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-47008
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform DoS attack on the target system.

The vulnerability exists due memory leak within the make_tempdir() and make_tempname() function in bucomm.c. A remote attacker can trick the victim to pass specially crafted data to the application and and perform denial of service attack.


Affected software

Binutils
Voice Gateway
Ubuntu
openEuler
binutils (Ubuntu package)
binutils-multiarch (Ubuntu package)
binutils-debuginfo
binutils-devel
binutils-debugsource
binutils-help
binutils
VMware Tanzu Operations Manager
VMware Tanzu Application Service for VMs
Isolation Segment
Platform Automation Toolkit
IBM Sterling Order Management

How to mitigate CVE-2022-47008

Install updates from vendor's website.

Binutils - update to 2.39
Voice Gateway - update to 1.0.8.12
binutils (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2.34-6ubuntu1.8, 2.38-4ubuntu2.5
binutils-multiarch (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2.34-6ubuntu1.8, 2.38-4ubuntu2.5
VMware Tanzu Operations Manager - update to 2.10.65
binutils-debuginfo - update to 2.34-26
binutils-devel - update to 2.34-26
binutils-debugsource - update to 2.34-26
binutils-help - update to 2.34-26
binutils - update to 2.34-26
VMware Tanzu Application Service for VMs - addressed in versions 3.0.19, 4.0.11
Isolation Segment - addressed in versions 3.0.19, 4.0.11
Platform Automation Toolkit - addressed in versions 4.0.13, 4.1.13, 4.2.8, 4.3.5
IBM Sterling Order Management - update to 10.0.2403.1

External References

Related Security Bulletins