Bug 2234003 (CVE-2021-46174)
| Summary: | CVE-2021-46174 binutils: heap-based buffer overflow in bfd_getl32() in libbfd.c via objdump | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | Guilherme de Almeida Suckevicz <gsuckevi> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | CLOSED NOTABUG | QA Contact: | |
| Severity: | low | Docs Contact: | |
| Priority: | low | ||
| Version: | unspecified | CC: | acrosby, ailan, bdettelb, caswilli, desktop-qa-list, fjansen, fweimer, gdb-bugs, hkataria, jburrell, jmitchel, jsamir, jsherril, jtanner, kaycoth, keiths, kshier, mcermak, mpolacek, mprchlik, nickc, ohudlick, psegedy, rjones, sipoyare, sthirugn, tsasak, virt-maint, vkrizan |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | No Doc Update | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2023-11-09 09:18:18 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2234006, 2234007, 2234008, 2234240, 2234241, 2234242, 2234243, 2234244, 2234245, 2234246, 2234247, 2234248, 2234249, 2234250, 2234251, 2234252, 2234253, 2234254 | ||
| Bug Blocks: | 2233947 | ||
|
Description
Guilherme de Almeida Suckevicz
2023-08-23 21:09:38 UTC
Created binutils tracking bugs for this issue: Affects: fedora-all [bug 2234006] Created gdb tracking bugs for this issue: Affects: fedora-all [bug 2234007] Created mingw-binutils tracking bugs for this issue: Affects: fedora-all [bug 2234008] (In reply to Guilherme de Almeida Suckevicz from comment #0) > Heap-based Buffer Overflow in function bfd_getl32 in Binutils objdump 3.37. The SECURITY.txt file found in the upstream GNU Binutils sources makes it clear that bug in inspection tools like objdump are not considered to be security issues, and hence do not qualify for CVE treatment. |