CVE-2018-6323 EXPLOIT
7.8
HIGH · CVSS 3.0 · EPSS 5.8% (pctl 93)
Patch early
A public exploit exists.
Description
The elf_object_p function in elfcode.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, has an unsigned integer overflow because bfd_size_type multiplication is not used. A crafted ELF file allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.
Scoring
| CVSS | 7.8 (HIGH, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| EPSS | 5.83% — more likely to be exploited than 93% of all CVEs |
| Weakness | CWE-190 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2018-01-26 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| gnu | binutils |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | GNU binutils 2.26.1 - Integer Overflow (PoC) | 2018-02-14 |
References
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00072.html
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00008.html
- http://www.securityfocus.com/bid/102821
- https://sourceware.org/bugzilla/show_bug.cgi?id=22746
- https://www.exploit-db.com/exploits/44035/
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00072.html
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00008.html
- http://www.securityfocus.com/bid/102821
- https://sourceware.org/bugzilla/show_bug.cgi?id=22746
- https://www.exploit-db.com/exploits/44035/
→ the Explorer · watch your stack · NVD