CVE-2024-53589 describes a high-severity buffer overflow vulnerability in GNU objdump 2.43, specifically within the BFD library's handling of tekhex format files. This flaw allows for local, low-complexity attacks without user interaction, potentially leading to high impact on confidentiality, integrity, and availability. While the CVSS score is 8.4, there is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| N/A | N/A | n/aCNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
GNU objdump 2.43 is vulnerable to Buffer Overflow in the BFD (Binary File Descriptor) library's handling of tekhex format files.
Dec 10, 2024binutils: objdump: buffer Overflow in the BFD library's handling of tekhex format files
Dec 5, 2024