CVE-2018-20002

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/12/2018
Last modified:
07/11/2023

Description

The _bfd_generic_read_minisymbols function in syms.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31, has a memory leak via a crafted ELF file, leading to a denial of service (memory consumption), as demonstrated by nm.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gnu:binutils:2.31:*:*:*:*:*:*:*
cpe:2.3:a:netapp:vasa_provider:*:*:*:*:*:*:*:* 7.2 (including)
cpe:2.3:o:netapp:cluster_data_ontap:-:*:*:*:*:*:*:*
cpe:2.3:a:f5:traffix_signaling_delivery_controller:*:*:*:*:*:*:*:* 5.0.0 (including) 5.1.0 (including)
cpe:2.3:a:f5:traffix_signaling_delivery_controller:4.4.0:*:*:*:*:*:*:*