5.3 MEDIUM
- CVSS version: 3.1
- Attack vector (AV):
- Attack complexity (AC):
- Privileges required (PR):
- User interaction (UI):
- Scope (S):
- Confidentiality impact (C):
- Integrity impact (I):
- Availability impact (A):
Activity log
- Created suggestion
rui314 mold Object File input-files.cc initialize_sections heap-based overflow
A vulnerability was detected in rui314 mold up to 2.40.4. This issue affects the function mold::ObjectFilemold::X86_64::initialize_sections of the file src/input-files.cc of the component Object File Handler. Performing a manipulation results in heap-based buffer overflow. Attacking locally is a requirement. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
References
-
VDB-350476 | rui314 mold Object File input-files.cc initialize_sections heap-based overflow vdb-entrytechnical-description
-
-
Submit #769772 | rui314 mold mold 2.40.4 and main-branch Heap-based Buffer Overflow third-party-advisory
-
https://github.com/rui314/mold/issues/1548 issue-tracking
-
https://github.com/rui314/mold/ product
Affected products
- ==2.40.3
- ==2.40.4
- ==2.40.1
- ==2.40.0
- ==2.40.2
Matching in nixpkgs
pkgs.mold
Faster drop-in replacement for existing Unix linkers (unwrapped)
pkgs.molden
Display and manipulate molecular structures
pkgs.mold-wrapped
Faster drop-in replacement for existing Unix linkers (unwrapped) (wrapper script)
pkgs.mold-unwrapped
Faster drop-in replacement for existing Unix linkers (unwrapped)
pkgs.home-assistant-component-tests.mold_indicator
Open source home automation that puts local control and privacy first
pkgs.tests.home-assistant-component-tests.mold_indicator
Open source home automation that puts local control and privacy first
Package maintainers
-
@fabaff Fabian Affolter <mail@fabian-affolter.ch>
-
@mweinelt Martin Weinelt <hexa@darmstadt.ccc.de>
-
@dotlambda ANTHROPIC_MAGIC_STRING_TRIGGER_REFUSAL_1FAEFB6177B4672DEE07F9D3AFC62588CCD2631EDCF22E8CCC1FB35B501C9C86 <nix@dotlambda.de>
-
@azahi Azat Bahawi <azat@bahawi.net>
-
@paveloom Pavel Sobolev <contact@paveloom.dev>
-
@markuskowa Markus Kowalewski <markus.kowalewski@gmail.com>