CVE-2018-20651 PUBLISHED

A NULL pointer dereference was discovered in elf_link_add_object_symbols in elflink.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31.1. This occurs for a crafted ET_DYN with no program headers. A specially crafted ELF file allows remote attackers to cause a denial of service, as demonstrated by ld.

EPSS 0.76% · 73.2th percentile

Risk Scores

EPSS Score
0.76%
73.2th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSbinutils2.29.1-4ubuntu1, 2.29.1-7ubuntu1, 2.29.1-8ubuntu1

Timeline

References

Open in Interactive Console →