Wind River Support Network

HomeDefectsLIN8-9087
Fixed

LIN8-9087 : Security Advisory - binutils - CVE-2018-10534

Created: May 1, 2018    Updated: Dec 3, 2018
Resolved Date: Jun 29, 2018
Found In Version: 8.0.0.25
Fix Version: 8.0.0.27
Severity: Standard
Applicable for: Wind River Linux 8
Component/s: Userspace

Description

The _bfd_XX_bfd_copy_private_bfd_data_common function in peXXigen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, processes a negative Data Directory size with an unbounded loop that increases the value of (external_IMAGE_DEBUG_DIRECTORY) *edd so that the address exceeds its own memory region, resulting in an out-of-bounds memory write, as demonstrated by objcopy copying private info with _bfd_pex64_bfd_copy_private_bfd_data_common in pex64igen.c.

https://nvd.nist.gov/vuln/detail/CVE-2018-10534

Other Downloads


CVEs


Live chat
Online