The vendor explicitly identifies these products as affected by this CVE.
- binutils-devel as a component of Red Hat Enterprise Linux 6
- binutils.src as a component of Red Hat Enterprise Linux 6
- Summary
- A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafted malicious XCOFF object file. Successful exploitation may lead to the disclosure of sensitive information or cause the application to crash, resulting in an application level denial of service.
- Remediation
- For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/
