CVE-2023-25584: Out of bounds read in parse_module function in bfd/vms-alpha.c
An out-of-bounds read flaw was found in the parsemodule function in bfd/vms-alpha.c in Binutils.
Other sources
GNU binutils is vulnerable to a denial of service, caused by an out-of-bounds read flaw in the parsemodule function in bfd/vms-alpha.c. By persuading a victim to open a specially crafted content, a remote attacker could exploit this vulnerability to cause a crash or access sensitive information.
— IBM
Out of bounds read flaws were found in Binutils in parsemodule function in bfd/vms-alpha.c
Upstream fix:
https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=77c225bdeb410cf60da804879ad41622f5f1aa44
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2023-25584?
CVE-2023-25584 is an out-of-bounds read vulnerability found in the parse_module function in bfd/vms-alpha.c in Binutils.
What is the severity of CVE-2023-25584?
The severity of CVE-2023-25584 is high with a CVSS score of 7.1.
How does CVE-2023-25584 affect GNU Binutils?
CVE-2023-25584 affects GNU Binutils through the parse_module function in bfd/vms-alpha.c.
How can I fix CVE-2023-25584?
To fix CVE-2023-25584, it is recommended to update to the latest version of Binutils.
Where can I find more information about CVE-2023-25584?
You can find more information about CVE-2023-25584 at the following references: [https://access.redhat.com/security/cve/CVE-2023-25584](https://access.redhat.com/security/cve/CVE-2023-25584), [https://bugzilla.redhat.com/show_bug.cgi?id=2167467](https://bugzilla.redhat.com/show_bug.cgi?id=2167467), [https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=77c225bdeb410cf60da804879ad41622f5f1aa44](https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=77c225bdeb410cf60da804879ad41622f5f1aa44).