CVE-2021-45078
Published on: Not Yet Published
Last Modified on: 09/28/2022 07:54:00 PM UTC
Certain versions of Debian Linux from Debian contain the following vulnerability:
stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds write. NOTE: this issue exists because of an incorrect fix for CVE-2018-12699.
- CVE-2021-45078 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
CVSS3 Score: 7.8 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
LOCAL | LOW | NONE | REQUIRED |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVSS2 Score: 6.8 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | MEDIUM | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
PARTIAL | PARTIAL | PARTIAL |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
GNU Binutils: Multiple Vulnerabilities (GLSA 202208-30) — Gentoo security | security.gentoo.org text/html |
![]() |
CVE-2021-45078 GNU Binutils Vulnerability in NetApp Products | NetApp Product Security | security.netapp.com text/html |
![]() |
[SECURITY] Fedora 34 Update: mingw-binutils-2.34-10.fc34 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org text/html |
![]() |
28694 – stabs.c: Out-of-bounds write in stab_xcoff_builtin_type | sourceware.org text/html |
![]() |
sourceware.org Git - binutils-gdb.git/commit | sourceware.org text/xml |
![]() |
[SECURITY] Fedora 35 Update: mingw-binutils-2.37-3.fc35 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org text/html |
![]() |
Related QID Numbers
- 282201 Fedora Security Update for mingw (FEDORA-2021-f2c6802743)
- 282202 Fedora Security Update for mingw (FEDORA-2021-3614c0b466)
- 296062 Oracle Solaris 11.4 Support Repository Update (SRU) 43.113.3 Missing (CPUJAN2022)
- 671375 EulerOS Security Update for binutils (EulerOS-SA-2022-1285)
- 671376 EulerOS Security Update for binutils (EulerOS-SA-2022-1301)
- 671414 EulerOS Security Update for binutils (EulerOS-SA-2022-1317)
- 671421 EulerOS Security Update for binutils (EulerOS-SA-2022-1341)
- 671496 EulerOS Security Update for binutils (EulerOS-SA-2022-1481)
- 671514 EulerOS Security Update for binutils (EulerOS-SA-2022-1500)
- 671710 EulerOS Security Update for binutils (EulerOS-SA-2022-1706)
- 710599 Gentoo Linux GNU Binutils Multiple Vulnerabilities (GLSA 202208-30)
- 752893 SUSE Enterprise Linux Security Update for binutils (SUSE-SU-2022:4146-1)
- 752941 SUSE Enterprise Linux Security Update for binutils (SUSE-SU-2022:4277-1)
- 900380 Common Base Linux Mariner (CBL-Mariner) Security Update for binutils (7026)
- 901907 Common Base Linux Mariner (CBL-Mariner) Security Update for binutils (7032-1)
Exploit/POC from Github
This repository contains a collection of data files on known Common Vulnerabilities and Exposures (CVEs). Each file i…
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Operating System | Debian | Debian Linux | 10.0 | All | All | All |
Operating System | Debian | Debian Linux | 11.0 | All | All | All |
Operating System | Debian | Debian Linux | 9.0 | All | All | All |
Operating System | Fedoraproject | Fedora | 34 | All | All | All |
Operating System | Fedoraproject | Fedora | 35 | All | All | All |
Application | Gnu | Binutils | All | All | All | All |
Application | Netapp | Ontap Select Deploy Administration Utility | - | All | All | All |
Operating System | Redhat | Enterprise Linux | 8.0 | All | All | All |
- cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*:
- cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*:
- cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*:
- cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*:
- cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*:
- cpe:2.3:a:gnu:binutils:*:*:*:*:*:*:*:*:
- cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:*:
- cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2021-45078 : stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers to cause a denial… twitter.com/i/web/status/1… | 2021-12-15 20:03:16 |
![]() |
Potentially Critical CVE Detected! CVE-2021-45078 Description: stab_xcoff_builtin_type in stabs.c in GNU Binutils t… twitter.com/i/web/status/1… | 2021-12-15 20:56:12 |
![]() |
CVE-2021-45078 | 2021-12-15 20:38:51 |