Bug 2234027 (CVE-2022-47695) - CVE-2022-47695 binutils: uninitialized field in bfd_mach_o_get_synthetic_symtab() in match-o.c
Summary: CVE-2022-47695 binutils: uninitialized field in bfd_mach_o_get_synthetic_symt...
Keywords:
Status: CLOSED NOTABUG
Alias: CVE-2022-47695
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2234031 2234032 2234033 2234300 2234301 2234302 2234303 2234304 2234305 2234306 2234307 2234308 2234309 2234310 2234311 2234312 2234313 2234314
Blocks: 2233947
TreeView+ depends on / blocked
 
Reported: 2023-08-23 22:16 UTC by Guilherme de Almeida Suckevicz
Modified: 2023-11-14 11:30 UTC (History)
29 users (show)

Fixed In Version:
Doc Type: No Doc Update
Doc Text:
Clone Of:
Environment:
Last Closed: 2023-11-09 09:18:58 UTC
Embargoed:


Attachments (Terms of Use)

Description Guilherme de Almeida Suckevicz 2023-08-23 22:16:26 UTC
An issue was discovered Binutils objdump before 2.39.3 allows attackers to cause a denial of service or other unspecified impacts via function bfd_mach_o_get_synthetic_symtab in match-o.c.

Reference:
https://sourceware.org/bugzilla/show_bug.cgi?id=29677

Comment 1 Guilherme de Almeida Suckevicz 2023-08-23 22:28:36 UTC
According to the description of this CVE in Mitre[1], the reference of this issue is this bug[2], however this bug seems related to CVE-2022-47696[3].

[1]. https://www.cve.org/CVERecord?id=CVE-2022-47695
[2]. https://sourceware.org/bugzilla/show_bug.cgi?id=29846
[3]. https://bugzilla.redhat.com/show_bug.cgi?id=2234029

Comment 2 Guilherme de Almeida Suckevicz 2023-08-23 22:30:59 UTC
Created binutils tracking bugs for this issue:

Affects: fedora-all [bug 2234031]


Created gdb tracking bugs for this issue:

Affects: fedora-all [bug 2234032]


Created mingw-binutils tracking bugs for this issue:

Affects: fedora-all [bug 2234033]

Comment 5 Nick Clifton 2023-08-24 13:05:11 UTC
(In reply to Guilherme de Almeida Suckevicz from comment #0)
> An issue was discovered Binutils objdump before 2.39.3 allows attackers to
> cause a denial of service or other unspecified impacts via function
> bfd_mach_o_get_synthetic_symtab in match-o.c.

The SECURITY.txt file found in the upstream GNU Binutils sources makes it clear that bug in inspection tools like objdump are not considered to be security issues, and hence do not qualify for CVE treatment.


Note You need to log in before you can comment on or make changes to this bug.