Vulnerability Description
A vulnerability has been found in GNU Binutils 2.43 and classified as problematic. Affected by this vulnerability is the function __sanitizer::internal_strlen of the file binutils/nm.c of the component nm. The manipulation of the argument const leads to buffer overflow. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gnu | Binutils | 2.43 |
Related Weaknesses (CWE)
References
- https://sourceware.org/bugzilla/attachment.cgi?id=15881Broken Link
- https://sourceware.org/bugzilla/show_bug.cgi?id=32556ExploitIssue Tracking
- https://vuldb.com/?ctiid.295051Permissions RequiredVDB Entry
- https://vuldb.com/?id.295051Third Party AdvisoryVDB Entry
- https://vuldb.com/?submit.485254ExploitThird Party AdvisoryVDB Entry
- https://www.gnu.org/Product
- https://security.netapp.com/advisory/ntap-20250404-0003/
FAQ
What is CVE-2025-1147?
CVE-2025-1147 is a vulnerability with a CVSS score of 3.1 (LOW). A vulnerability has been found in GNU Binutils 2.43 and classified as problematic. Affected by this vulnerability is the function __sanitizer::internal_strlen of the file binutils/nm.c of the componen...
How severe is CVE-2025-1147?
CVE-2025-1147 has been rated LOW with a CVSS base score of 3.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-1147?
Check the references section above for vendor advisories and patch information. Affected products include: Gnu Binutils.