CVE-2018-7569 describes an integer underflow or overflow vulnerability in the Binary File Descriptor (BFD) library (libbfd) within GNU Binutils 2.30. This flaw, specifically in dwarf2.c, allows remote attackers to trigger a denial of service (application crash) by providing a specially crafted ELF file with a corrupt DWARF FORM block. Affected products include various versions of GNU Binutils and Red Hat Enterprise Linux. Rated with a CVSS score of 5.5 (Medium), this vulnerability requires user interaction (UI:R) for exploitation, typically by processing a malicious ELF file, and has low attack complexity (AC:L). The primary impact is a denial of service (A:H), with no direct impact on confidentiality or integrity. There is no evidence of active exploitation, nor is exploit code publicly available on platforms like Metasploit or ExploitDB. Community discussion and media coverage for this CVE are minimal, indicating a low level of public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.30CPE matchmatch criteria | cpe:2.3:a:gnu:binutils:2.30:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.