Bug 2233930 (CVE-2020-19724)

Summary: CVE-2020-19724 binutils: memory leak in get_data() in nm.c
Product: [Other] Security Response Reporter: Guilherme de Almeida Suckevicz <gsuckevi>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: CLOSED NOTABUG QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: acrosby, ailan, bdettelb, caswilli, darunesh, desktop-qa-list, fjansen, fweimer, gdb-bugs, hkataria, jburrell, jmitchel, jsamir, jsherril, jtanner, kaycoth, keiths, kshier, mcermak, mdogra, mpolacek, mprchlik, nickc, ohudlick, psegedy, rjones, sipoyare, sthirugn, tsasak, virt-maint, vkrizan
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
A memory consumption issue was identified in binutils in get_data() function in nm.c file. This flaws could allow attackers to cause a denial of service via crafted command.
Story Points: ---
Clone Of: Environment:
Last Closed: 2023-10-30 09:25:52 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2233935, 2233936, 2233937, 2234043, 2234044, 2234045, 2234046, 2234047, 2234048, 2234049, 2234050, 2234051, 2234052, 2234053, 2234054, 2234055, 2234056, 2234057    
Bug Blocks: 2233947    

Description Guilherme de Almeida Suckevicz 2023-08-23 18:49:35 UTC
A memory consumption issue in get_data function in binutils/nm.c in GNU nm before 2.34 allows attackers to cause a denial of service via crafted command.

References:
https://sourceware.org/bugzilla/show_bug.cgi?id=25362
https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=805f38bc551de820bcd7b31d3c5731ae27cf853a

Comment 1 Guilherme de Almeida Suckevicz 2023-08-23 19:10:14 UTC
Created binutils tracking bugs for this issue:

Affects: fedora-all [bug 2233935]


Created gdb tracking bugs for this issue:

Affects: fedora-all [bug 2233936]


Created mingw-binutils tracking bugs for this issue:

Affects: fedora-all [bug 2233937]