Vulnerability   
Search   
    Search 191973 CVE descriptions
and 86218 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.1.2.2020.2226
Category:Huawei EulerOS Local Security Checks
Title:Huawei EulerOS: Security Advisory for binutils (EulerOS-SA-2020-2226)
Summary:The remote host is missing an update for the Huawei EulerOS; 'binutils' package(s) announced via the EulerOS-SA-2020-2226 advisory.
Description:Summary:
The remote host is missing an update for the Huawei EulerOS
'binutils' package(s) announced via the EulerOS-SA-2020-2226 advisory.

Vulnerability Insight:
The _bfd_generic_read_minisymbols function in syms.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31, has a memory leak via a crafted ELF file, leading to a denial of service (memory consumption), as demonstrated by nm.(CVE-2018-20002)

apply_relocations in readelf.c in GNU Binutils 2.32 contains an integer overflow that allows attackers to trigger a write access violation (in byte_put_little_endian function in elfcomm.c) via an ELF file, as demonstrated by readelf.(CVE-2019-14444)

Affected Software/OS:
'binutils' package(s) on Huawei EulerOS Virtualization 3.0.2.2.

Solution:
Please install the updated package(s).

CVSS Score:
4.3

CVSS Vector:
AV:N/AC:M/Au:N/C:N/I:N/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2018-20002
Common Vulnerability Exposure (CVE) ID: CVE-2019-14444
CopyrightCopyright (C) 2020 Greenbone Networks GmbH

This is only one of 86218 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2020 E-Soft Inc. All rights reserved.