CVE-2018-6759
5.5
MEDIUM
CVSS 3.1
EPSS 0.18%
Description
The bfd_get_debug_link_info_1 function in opncls.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, has an unchecked strnlen operation. Remote attackers could leverage this vulnerability to cause a denial of service (segmentation fault) via a crafted ELF file.
How to fix CVE-2018-6759
To remediate CVE-2018-6759, upgrade the affected package to a fixed version below.
- Alpine/binutils—upgrade to 2.30-r2 or later
- —upgrade to 2.30-3 or later
Is CVE-2018-6759 being exploited?
Low — EPSS is 0.2%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 2.30-r2
- from 0, < 2.30-3
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.5 | CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |