GNU Binutils elf.c bfd_elf_set_group_contents out-of-bounds write
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 4.8epss 0.2%
exploitation probability
0.2%top 92% of all CVEs
observed exploitation
nono source reports it
A vulnerability, which was classified as problematic, has been found in GNU Binutils 2.45. Affected by this issue is the function bfd_elf_set_group_contents of the file bfd/elf.c. The manipulation leads to out-of-bounds write. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The name of the patch is 41461010eb7c79fee7a9d5f6209accdaac66cc6b. It is recommended to apply a patch to fix this issue.
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Affected products
GNU · BinutilsReferences
https://cert-portal.siemens.com/productcert/html/ssa-082556.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-265688.htmlhttps://sourceware.org/bugzilla/attachment.cgi?id=16118https://sourceware.org/bugzilla/show_bug.cgi?id=33050https://sourceware.org/bugzilla/show_bug.cgi?id=33050#c2https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=41461010eb7c79fee7a9d5f6209accdaac66cc6bhttps://vuldb.com/?ctiid.316244https://vuldb.com/?id.316244https://vuldb.com/?submit.614375https://www.gnu.org/