CVE-2018-12699: Buffer Overflow
A flaw was found in finishstab in stabs.c in GNU Binutils 2.30 which allows attackers to cause a denial of service (heap-based buffer overflow) as demonstrated by an out-of-bounds write of 8 bytes.
References: https://bugs.launchpad.net/ubuntu/+source/binutils/+bug/1763102 https://gcc.gnu.org/bugzilla/showbug.cgi?id=85454 https://sourceware.org/bugzilla/showbug.cgi?id=23057
Other sources
finishstab in stabs.c in GNU Binutils 2.30 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds write of 8 bytes. This can occur during execution of objdump.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2018-12699.
What is the severity of CVE-2018-12699?
The severity of CVE-2018-12699 is not specified, but it can cause a denial of service (DoS) or potentially have other unspecified impacts.
How does CVE-2018-12699 affect GNU Binutils?
CVE-2018-12699 affects GNU Binutils version 2.30.
What is the impact of CVE-2018-12699?
The impact of CVE-2018-12699 is a heap-based buffer overflow, which can cause a denial of service (DoS) or other unspecified impacts.
How can I fix CVE-2018-12699?
To fix CVE-2018-12699, update GNU Binutils to version 2.32.51.20190707-1 or later.