Out-of-bounds read in Binutils - CVE-2023-25584
Published: March 5, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary condition within the parse_module() function in bfd/vms-alpha.c. A remote attacker can pass specially crafted input to the application, trigger an out-of-bounds read error and perform a denial of service (DoS) attack.
Affected software
IBM Cloud Pak for Security
Chrome OS
How to mitigate CVE-2023-25584
IBM Cloud Pak for Security - update to 1.11.2.0
Chrome OS - update to 120.0.6099.310