CVE-2022-4285
27.01.2023, 18:15
An illegal memory access flaw was found in the binutils package. Parsing an ELF file containing corrupt symbol version information may result in a denial of service. This issue is the result of an incomplete fix for CVE-2020-16599.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| gnu | binutils | 2.35 ≤ 𝑥 < 2.39-7 |
| redhat | enterprise_linux | 6.0 |
| redhat | enterprise_linux | 7.0 |
| redhat | enterprise_linux | 8.0 |
| redhat | enterprise_linux | 9.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| binutils |
| ||||||||||||||||||
| binutils-avr |
| ||||||||||||||||||
| gdb |
|
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| binutils |
| ||||||||||||||||||||||||||||||||||||||||||
| binutils-devel |
| ||||||||||||||||||||||||||||||||||||||||||
| binutils-devel-32bit |
| ||||||||||||||||||||||||||||||||||||||||||
| libctf-nobfd0 |
| ||||||||||||||||||||||||||||||||||||||||||
| libctf0 |
|
Red Hat Enterprise Linux Releases
Red Hat Product | |||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| binutils |
| ||||||||||||||||||||
| binutils-devel |
| ||||||||||||||||||||
| binutils-gold |
| ||||||||||||||||||||
| gcc-toolset-12-binutils |
| ||||||||||||||||||||
| gcc-toolset-12-binutils-devel |
| ||||||||||||||||||||
| gcc-toolset-12-binutils-gold |
|
Common Weakness Enumeration
References