In GNU Binutils before 2.40, there is a heap-buffer-overflow in the error function bfd_getl32 when called from the strip_main function in strip-new via a crafted file.
References
Link | Resource |
---|---|
https://sourceware.org/bugzilla/show_bug.cgi?id=29482 | Issue Tracking Patch Third Party Advisory |
https://sourceware.org/bugzilla/show_bug.cgi?id=29482#c2 | Issue Tracking Patch Third Party Advisory |
https://security.netapp.com/advisory/ntap-20221104-0007/ | Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6AKZ2DTS3ATVN5PANNVLKLE5OP4OF25Q/ | Mailing List Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7MTEHT3G6YKJ7F7MSGWYSI4UM3XBAYXZ/ | Mailing List Third Party Advisory |
Information
Published : 2022-08-25 17:15
Updated : 2022-12-07 19:46
NVD link : CVE-2022-38533
Mitre link : CVE-2022-38533
JSON object : View
CWE
CWE-787
Out-of-bounds Write
Products Affected
gnu
- binutils
fedoraproject
- fedora