A vulnerability classified as critical has been found in GNU Binutils up to 2.44. This affects the function debug_type_samep of the file /binutils/debug.c of the component objdump. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.
History

Wed, 28 May 2025 03:45:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 27 May 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 27 May 2025 14:45:00 +0000

Type Values Removed Values Added
Description A vulnerability classified as critical has been found in GNU Binutils up to 2.44. This affects the function debug_type_samep of the file /binutils/debug.c of the component objdump. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.
Title GNU Binutils objdump debug.c debug_type_samep memory corruption
Weaknesses CWE-119
References
Metrics cvssV2_0

{'score': 4.3, 'vector': 'AV:L/AC:L/Au:S/C:P/I:P/A:P'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-05-27T14:31:12.173Z

Updated: 2025-05-27T15:20:54.076Z

Reserved: 2025-05-27T08:07:06.452Z

Link: CVE-2025-5245

cve-icon Vulnrichment

Updated: 2025-05-27T15:20:50.875Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-05-27T15:15:36.057

Modified: 2025-05-28T15:01:30.720

Link: CVE-2025-5245

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-05-27T14:31:12Z

Links: CVE-2025-5245 - Bugzilla