Metrics
Affected Vendors & Products
Thu, 23 Oct 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:gnu:binutils:2.45:*:*:*:*:*:*:* |
Mon, 20 Oct 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gnu
Gnu binutils |
|
| Vendors & Products |
Gnu
Gnu binutils |
Fri, 17 Oct 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 16 Oct 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 16 Oct 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A weakness has been identified in GNU Binutils 2.45. The affected element is the function vfinfo of the file ldmisc.c. Executing manipulation can lead to out-of-bounds read. The attack can only be executed locally. The exploit has been made available to the public and could be exploited. This patch is called 16357. It is best practice to apply a patch to resolve this issue. | |
| Title | GNU Binutils ldmisc.c vfinfo out-of-bounds | |
| Weaknesses | CWE-119 CWE-125 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published: 2025-10-16T15:32:11.651Z
Updated: 2025-10-16T18:12:26.436Z
Reserved: 2025-10-16T08:36:17.235Z
Link: CVE-2025-11840
Updated: 2025-10-16T18:12:03.442Z
Status : Analyzed
Published: 2025-10-16T16:15:37.003
Modified: 2025-10-23T19:41:21.713
Link: CVE-2025-11840