#VU103993 Buffer overflow in Binutils - CVE-2025-1181
Published: February 17, 2025
Binutils
GNU
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error within the _bfd_elf_gc_mark_rsec() function in bfd/elflink.c within the ld binary. A remote attacker can pass specially crafted input to the binary, trigger memory corruption and execute arbitrary code on the target system.
Remediation
External links
- https://sourceware.org/bugzilla/attachment.cgi?id=15918
- https://sourceware.org/bugzilla/show_bug.cgi?id=32643
- https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=931494c9a89558acb36a03a340c01726545eef24
- https://vuldb.com/?ctiid.295084
- https://vuldb.com/?id.295084
- https://vuldb.com/?submit.495402