The _bfd_slurp_extended_name_table function in bfd/archive.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (invalid write, segmentation fault, and crash) via a crafted extended name table in an archive.
CVSS Details
- CVSS 3.1 Base Score: 5.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade binutilsUpgrade binutils-mingw-w64 | Jul 30, 2024 | Jan 15, 2015 |
| Gentoo Linux | — | Upgrade sys-devel/binutils. | Oct 30, 2017 | Jan 15, 2015 |
| Oracle_linux | — | Upgrade binutils-develUpgrade binutils | Oct 16, 2024 | Jan 15, 2015 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Nov 2, 2014 |
| Suse | — | Upgrade binutils-develUpgrade binutilsUpgrade cross-spu-binutilsUpgrade binutils-devel-32bitUpgrade cross-ppc-binutilsUpgrade binutils-gold | Dec 18, 2015 | Jan 15, 2015 |
| Ubuntu | — | Upgrade binutilsUpgrade binutils-multiarch | Nov 8, 2024 | Jan 15, 2015 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jan 15, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub