Use of Externally-Controlled Format String Affecting binutils package, versions <2.18.1~cvs20080103-1
Snyk CVSS
Attack Complexity
Low
User Interaction
Required
Threat Intelligence
EPSS
0.28% (68th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-DEBIAN11-BINUTILS-522393
- published 1 Jul 2008
- disclosed 1 Jul 2008
Introduced: 1 Jul 2008
CVE-2008-2310 Open this link in a new tabHow to fix?
Upgrade Debian:11
binutils
to version 2.18.1~cvs20080103-1 or higher.
NVD Description
Note: Versions mentioned in the description apply only to the upstream binutils
package and not the binutils
package as distributed by Debian
.
See How to fix?
for Debian:11
relevant fixed versions and status.
Format string vulnerability in c++filt in Apple Mac OS X 10.5 before 10.5.4 allows user-assisted attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted string in (1) C++ or (2) Java source code.
References
- https://security-tracker.debian.org/tracker/CVE-2008-2310
- http://support.apple.com/kb/HT2163
- http://lists.apple.com/archives/security-announce/2008//Jun/msg00002.html
- http://securitytracker.com/id?1020392
- http://www.vupen.com/english/advisories/2008/1981/references
- http://xforce.iss.net/xforce/xfdb/43494
- http://secunia.com/advisories/30802
- http://www.securityfocus.com/bid/30018
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43494