The vendor explicitly identifies these products as affected by this CVE.
- mingw-binutils-generic as a component of Red Hat Enterprise Linux 10
- mingw32-binutils as a component of Red Hat Enterprise Linux 10
- mingw64-binutils as a component of Red Hat Enterprise Linux 10
- gdb as a component of Red Hat Enterprise Linux 8
- gdb-doc as a component of Red Hat Enterprise Linux 8
- gdb-gdbserver as a component of Red Hat Enterprise Linux 8
- gdb-headless as a component of Red Hat Enterprise Linux 8
- gdb.src as a component of Red Hat Enterprise Linux 8
- mingw-binutils-generic as a component of Red Hat Enterprise Linux 8
- mingw-binutils.src as a component of Red Hat Enterprise Linux 8
- mingw32-binutils as a component of Red Hat Enterprise Linux 8
- mingw64-binutils as a component of Red Hat Enterprise Linux 8
- Summary
- A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious file, which could lead to arbitrary code execution, allowing the attacker to run unauthorized commands, or cause a denial of service, making the system unavailable.
- Remediation
- For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/
