CVE-2018-20671 PUBLISHED

load_specific_debug_section in objdump.c in GNU Binutils through 2.31.1 contains an integer overflow vulnerability that can trigger a heap-based buffer overflow via a crafted section size.

EPSS 0.11% · 29.4th percentile

Risk Scores

EPSS Score
0.11%
29.4th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSbinutils2.30-21ubuntu1~18.04.2, 2.30-21ubuntu1~18.04.1, 2.30-21ubuntu1~18.04
Ubuntu:Pro:14.04:LTSbinutils2.24-5ubuntu14.2+esm2, 2.24-5ubuntu14.2+esm3, 2.24-5ubuntu14.2
Ubuntu:Pro:16.04:LTSbinutils2.26-7ubuntu2, 2.26-8ubuntu1, 2.26-8ubuntu2

Timeline

References

Open in Interactive Console →