CVE-2018-20671

Severity CVSS v4.0:
Pending analysis
Type:
CWE-190 Integer Overflow or Wraparound
Publication date:
04/01/2019
Last modified:
07/11/2023

Description

load_specific_debug_section in objdump.c in GNU Binutils through 2.31.1 contains an integer overflow vulnerability that can trigger a heap-based buffer overflow via a crafted section size.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gnu:binutils:*:*:*:*:*:*:*:* 2.31.1 (including)