Linux Distros Unpatched Vulnerability : CVE-2025-1178

medium Nessus Plugin ID 230756

Synopsis

The Linux/Unix host has one or more packages installed with a vulnerability that the vendor indicates will not be patched.

Description

The Linux/Unix host has one or more packages installed that are impacted by a vulnerability without a vendor supplied patch available.

- A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. Affected by this vulnerability is the function bfd_putl64 of the file libbfd.c of the component ld. The manipulation leads to memory corruption. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The identifier of the patch is 75086e9de1707281172cc77f178e7949a4414ed0. It is recommended to apply a patch to fix this issue. (CVE-2025-1178)

Note that Nessus relies on the presence of the package as reported by the vendor.

Solution

There is no known solution at this time.

See Also

https://access.redhat.com/security/cve/cve-2025-1178

https://security-tracker.debian.org/tracker/CVE-2025-1178

https://ubuntu.com/security/CVE-2025-1178

Plugin Details

Severity: Medium

ID: 230756

File Name: unpatched_CVE_2025_1178.nasl

Version: 1.5

Type: local

Agent: unix

Family: Misc.

Published: 3/6/2025

Updated: 10/14/2025

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.2

CVSS v2

Risk Factor: Medium

Base Score: 4.3

Temporal Score: 3.9

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:N/A:P

CVSS Score Source: CVE-2025-1178

CVSS v3

Risk Factor: Medium

Base Score: 5.6

Temporal Score: 5.3

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L

Temporal Vector: CVSS:3.0/E:P/RL:U/RC:C

Vulnerability Information

CPE: p-cpe:/a:canonical:ubuntu_linux:binutils, cpe:/o:canonical:ubuntu_linux:16.04:-:lts, cpe:/o:debian:debian_linux:11.0, p-cpe:/a:redhat:enterprise_linux:mingw32-binutils, p-cpe:/a:redhat:enterprise_linux:mingw64-binutils, cpe:/o:canonical:ubuntu_linux:25.10, cpe:/o:debian:debian_linux:13.0, cpe:/o:redhat:enterprise_linux:9, cpe:/o:canonical:ubuntu_linux:25.04, cpe:/o:canonical:ubuntu_linux:18.04:-:lts, p-cpe:/a:redhat:enterprise_linux:mingw-binutils, p-cpe:/a:redhat:enterprise_linux:mingw-binutils-generic, cpe:/o:canonical:ubuntu_linux:14.04:-:lts, p-cpe:/a:debian:debian_linux:binutils, cpe:/o:debian:debian_linux:12.0

Required KB Items: Host/local_checks_enabled, Host/cpu, global_settings/vendor_unpatched, Host/OS/identifier

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 2/11/2025

Reference Information

CVE: CVE-2025-1178