CVE-2022-38533
Dashboard / Vulnerabilities / CVE-2022-38533
CVE-2022-38533
Summary:
Details: In GNU Binutils before 2.40, there is a heap-buffer-overflow in the error function bfd_getl32 when called from the strip_main function in strip-new via a crafted file.
References: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git%3Bh=45d92439aebd0386ef8af76e1796d08cfe457e1d, https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/38xxx/CVE-2022-38533.json, https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6AKZ2DTS3ATVN5PANNVLKLE5OP4OF25Q/, https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7MTEHT3G6YKJ7F7MSGWYSI4UM3XBAYXZ/, https://nvd.nist.gov/vuln/detail/CVE-2022-38533, https://security.gentoo.org/glsa/202309-15, https://security.netapp.com/advisory/ntap-20221104-0007/, https://sourceware.org/bugzilla/show_bug.cgi?id=29482, https://sourceware.org/bugzilla/show_bug.cgi?id=29482#c2, https://sourceware.org/bugzilla/show_bug.cgi?id=29495, https://github.com/bminor/binutils-gdb/commit/45d92439aebd0386ef8af76e1796d08cfe457e1d
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
