CVE-2022-4285

An illegal memory access flaw was found in the binutils package. Parsing an ELF file containing corrupt symbol version information may result in a denial of service. This issue is the result of an incomplete fix for CVE-2020-16599.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gnu:binutils:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*

History

21 Nov 2024, 07:34

Type Values Removed Values Added
References () https://bugzilla.redhat.com/show_bug.cgi?id=2150768 - Exploit, Issue Tracking, Patch, Third Party Advisory () https://bugzilla.redhat.com/show_bug.cgi?id=2150768 - Exploit, Issue Tracking, Patch, Third Party Advisory
References () https://security.gentoo.org/glsa/202309-15 - () https://security.gentoo.org/glsa/202309-15 -
References () https://sourceware.org/bugzilla/show_bug.cgi?id=29699 - Exploit, Issue Tracking, Patch, Vendor Advisory () https://sourceware.org/bugzilla/show_bug.cgi?id=29699 - Exploit, Issue Tracking, Patch, Vendor Advisory
References () https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git%3Bh=5c831a3c7f3ca98d6aba1200353311e1a1f84c70 - () https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git%3Bh=5c831a3c7f3ca98d6aba1200353311e1a1f84c70 -
Summary
  • (es) Se encontró una falla de acceso ilegal a la memoria en el paquete binutils. El parseo de un archivo ELF que contiene información de versión de símbolo corrupta puede resultar en una denegación de servicio. Este problema es el resultado de una solución incompleta para CVE-2020-16599.

07 Nov 2023, 03:57

Type Values Removed Values Added
CWE CWE-476
References
  • {'url': 'https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=5c831a3c7f3ca98d6aba1200353311e1a1f84c70', 'name': 'https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=5c831a3c7f3ca98d6aba1200353311e1a1f84c70', 'tags': ['Mailing List', 'Patch', 'Vendor Advisory'], 'refsource': 'MISC'}
  • () https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git%3Bh=5c831a3c7f3ca98d6aba1200353311e1a1f84c70 -

30 Sep 2023, 10:15

Type Values Removed Values Added
CWE CWE-476
References
  • (GENTOO) https://security.gentoo.org/glsa/202309-15 -

Information

Published : 2023-01-27 18:15

Updated : 2024-11-21 07:34


NVD link : CVE-2022-4285

Mitre link : CVE-2022-4285

CVE.ORG link : CVE-2022-4285


JSON object : View

Products Affected

fedoraproject

  • fedora

redhat

  • enterprise_linux

gnu

  • binutils
CWE
CWE-476

NULL Pointer Dereference