CVE-2018-12699
published 2018-06-23CVE-2018-12699: finish_stab in stabs.c in GNU Binutils 2.30 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other…
PriorityP341critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
4.50%
90.5th percentile
finish_stab in stabs.c in GNU Binutils 2.30 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds write of 8 bytes. This can occur during execution of objdump.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | binutils | < binutils 2.32.51.20190707-1 (bookworm) | binutils 2.32.51.20190707-1 (bookworm) |
| debian | binutils | < binutils 2.37.50.20220106-1 (bookworm) | binutils 2.37.50.20220106-1 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| gnu | binutils | <= 2.37 | — |
| gnu | binutils | — | — |
| gnu | binutils | >= 0 < 2.32.51.20190707-1 | 2.32.51.20190707-1 |
| gnu | binutils | >= 0 < 2.37.50.20220106-1 | 2.37.50.20220106-1 |
| gnu | binutils | >= 0 < 2.32.51.20190707-1 | 2.32.51.20190707-1 |
| gnu | binutils | >= 0 < 2.37.50.20220106-1 | 2.37.50.20220106-1 |
| gnu | binutils | >= 0 < 2.32.51.20190707-1 | 2.32.51.20190707-1 |
| gnu | binutils | >= 0 < 2.37.50.20220106-1 | 2.37.50.20220106-1 |
| gnu | binutils | >= 0 < 2.32.51.20190707-1 | 2.32.51.20190707-1 |
| msrc | cbl2_binutils_2.37-3_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_binutils_2.36.1-2_on_cbl_mariner_1.0 | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8LOW
vendor_redhat9.8CRITICAL
vendor_msrc7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r4rx-vwmc-mj74: finish_stab in stabs
ghsa_unreviewed·2022-05-14
CVE-2018-12699 [CRITICAL] CWE-787 GHSA-r4rx-vwmc-mj74: finish_stab in stabs
finish_stab in stabs.c in GNU Binutils 2.30 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds write of 8 bytes. This can occur during execution of objdump.
GHSA
GHSA-wg2c-jc4j-gg9c: stab_xcoff_builtin_type in stabs
ghsa_unreviewed·2021-12-16·CVSS 9.8
CVE-2021-45078 [CRITICAL] CWE-787 GHSA-wg2c-jc4j-gg9c: stab_xcoff_builtin_type in stabs
stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds write. NOTE: this issue exists because of an incorrect fix for CVE-2018-12699.
OSV
CVE-2021-45078: stab_xcoff_builtin_type in stabs
osv·2021-12-15·CVSS 9.8
CVE-2021-45078 [CRITICAL] CVE-2021-45078: stab_xcoff_builtin_type in stabs
stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds write. NOTE: this issue exists because of an incorrect fix for CVE-2018-12699.
OSV
CVE-2018-12699: finish_stab in stabs
osv·2018-06-23·CVSS 9.8
CVE-2018-12699 [CRITICAL] CVE-2018-12699: finish_stab in stabs
finish_stab in stabs.c in GNU Binutils 2.30 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds write of 8 bytes. This can occur during execution of objdump.
Red Hat
binutils: out-of-bounds write in stab_xcoff_builtin_type() in stabs.c
vendor_redhat·2021-12-14·CVSS 9.8
CVE-2021-45078 [CRITICAL] CWE-787 binutils: out-of-bounds write in stab_xcoff_builtin_type() in stabs.c
binutils: out-of-bounds write in stab_xcoff_builtin_type() in stabs.c
stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds write. NOTE: this issue exists because of an incorrect fix for CVE-2018-12699.
An out-of-bounds flaw was found in binutils’ stabs functionality. The attack needs to be initiated locally where an attacker could convince a victim to read a specially crafted file that is processed by objdump, leading to the disclosure of memory and possibly leading to the execution of arbitrary code or causing the utility to crash.
Statement: The issue is classified as moderate severity primarily because binutils is not typ
Microsoft
stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact as demonstrated by
vendor_msrc·2021-12-14·CVSS 7.8
CVE-2021-45078 [CRITICAL] CWE-787 stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact as demonstrated by
stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact as demonstrated by an out-of-bounds write. NOTE: this issue exists because of an incorrect fix for CVE-2018-12699.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blo
Ubuntu
GNU binutils vulnerabilities
vendor_ubuntu·2021-07-21
CVE-2018-19932 GNU binutils vulnerabilities
Title: GNU binutils vulnerabilities
Summary: Several security issues were fixed in GNU binutils.
USN-4336-1 fixed several vulnerabilities in GNU binutils. This update provides
the corresponding update for Ubuntu 16.04 ESM.
Original advisory details:
It was discovered that GNU binutils contained a large number of security
issues. If a user or automated system were tricked into processing a
specially-crafted file, a remote attacker could cause GNU binutils to
crash, resulting in a denial of service, or possibly execute arbitrary
code.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2021-45078: binutils - stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers...
vendor_debian·2021·CVSS 9.8
CVE-2021-45078 [CRITICAL] CVE-2021-45078: binutils - stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers...
stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds write. NOTE: this issue exists because of an incorrect fix for CVE-2018-12699.
Scope: local
bookworm: resolved (fixed in 2.37.50.20220106-1)
bullseye: open
forky: resolved (fixed in 2.37.50.20220106-1)
sid: resolved (fixed in 2.37.50.20220106-1)
trixie: resolved (fixed in 2.37.50.20220106-1)
Ubuntu
GNU binutils vulnerabilities
vendor_ubuntu·2020-04-22
CVE-2018-1000876 GNU binutils vulnerabilities
Title: GNU binutils vulnerabilities
Summary: Several security issues were fixed in GNU binutils.
It was discovered that GNU binutils contained a large number of security
issues. If a user or automated system were tricked into processing a
specially-crafted file, a remote attacker could cause GNU binutils to
crash, resulting in a denial of service, or possibly execute arbitrary
code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
binutils: heap-based buffer overflow in finish_stab in stabs.c
vendor_redhat·2018-04-11·CVSS 9.8
CVE-2018-12699 [CRITICAL] CWE-122 binutils: heap-based buffer overflow in finish_stab in stabs.c
binutils: heap-based buffer overflow in finish_stab in stabs.c
finish_stab in stabs.c in GNU Binutils 2.30 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds write of 8 bytes. This can occur during execution of objdump.
Statement: This is a vulnerability affecting binutils, a suite of tools for managing binaries on a linux system; as these tools are used by developers in compilation and debugging, the expected use case is a local user examining object files on a local filesystem, or using ssh to log in. Because of differences in how upstream sources and other vendors provide these utilities, other sources might report the impact of this flaw differently. However, while it is possible fo
Debian
CVE-2018-12699: binutils - finish_stab in stabs.c in GNU Binutils 2.30 allows attackers to cause a denial o...
vendor_debian·2018·CVSS 9.8
CVE-2018-12699 [CRITICAL] CVE-2018-12699: binutils - finish_stab in stabs.c in GNU Binutils 2.30 allows attackers to cause a denial o...
finish_stab in stabs.c in GNU Binutils 2.30 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds write of 8 bytes. This can occur during execution of objdump.
Scope: local
bookworm: resolved (fixed in 2.32.51.20190707-1)
bullseye: resolved (fixed in 2.32.51.20190707-1)
forky: resolved (fixed in 2.32.51.20190707-1)
sid: resolved (fixed in 2.32.51.20190707-1)
trixie: resolved (fixed in 2.32.51.20190707-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2021-45078 binutils: out-of-bounds write in stab_xcoff_builtin_type() in stabs.c
bugzilla·2021-12-17·CVSS 9.8
CVE-2021-45078 [CRITICAL] CVE-2021-45078 binutils: out-of-bounds write in stab_xcoff_builtin_type() in stabs.c
CVE-2021-45078 binutils: out-of-bounds write in stab_xcoff_builtin_type() in stabs.c
stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds write. NOTE: this issue exists because of an incorrect fix for CVE-2018-12699.
Reference:
https://sourceware.org/bugzilla/show_bug.cgi?id=28694
Upstream patch:
https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=161e87d12167b1e36193385485c1f6ce92f74f02
Discussion:
Created binutils tracking bugs for this issue:
Affects: fedora-all [bug 2033716]
Created mingw-binutils tracking bugs for this issue:
Affects: fedora-all [bug 2033717]
---
This is not security-relevant as per the b
Bugzilla
CVE-2018-12699 binutils: heap-based buffer overflow in finish_stab in stabs.c [fedora-all]
bugzilla·2018-06-26·CVSS 9.8
CVE-2018-12699 [CRITICAL] CVE-2018-12699 binutils: heap-based buffer overflow in finish_stab in stabs.c [fedora-all]
CVE-2018-12699 binutils: heap-based buffer overflow in finish_stab in stabs.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple suppo
Bugzilla
CVE-2018-12699 binutils: heap-based buffer overflow in finish_stab in stabs.c
bugzilla·2018-06-26·CVSS 9.8
CVE-2018-12699 [CRITICAL] CVE-2018-12699 binutils: heap-based buffer overflow in finish_stab in stabs.c
CVE-2018-12699 binutils: heap-based buffer overflow in finish_stab in stabs.c
A flaw was found in finish_stab in stabs.c in GNU Binutils 2.30 which allows attackers to cause a denial of service (heap-based buffer overflow) as demonstrated by an out-of-bounds write of 8 bytes.
References:
https://bugs.launchpad.net/ubuntu/+source/binutils/+bug/1763102
https://gcc.gnu.org/bugzilla/show_bug.cgi?id=85454
https://sourceware.org/bugzilla/show_bug.cgi?id=23057
Discussion:
Created binutils tracking bugs for this issue:
Affects: fedora-all [bug 1595435]
Created mingw-binutils tracking bugs for this issue:
Affects: epel-all [bug 1595433]
Affects: fedora-all [bug 1595432]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2024:9689 https://ac
Bugzilla
CVE-2018-12699 mingw-binutils: binutils: heap-based buffer overflow in finish_stab in stabs.c [epel-all]
bugzilla·2018-06-26·CVSS 9.8
CVE-2018-12699 [CRITICAL] CVE-2018-12699 mingw-binutils: binutils: heap-based buffer overflow in finish_stab in stabs.c [epel-all]
CVE-2018-12699 mingw-binutils: binutils: heap-based buffer overflow in finish_stab in stabs.c [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects mu
Bugzilla
CVE-2018-12699 mingw-binutils: binutils: heap-based buffer overflow in finish_stab in stabs.c [fedora-all]
bugzilla·2018-06-26·CVSS 9.8
CVE-2018-12699 [CRITICAL] CVE-2018-12699 mingw-binutils: binutils: heap-based buffer overflow in finish_stab in stabs.c [fedora-all]
CVE-2018-12699 mingw-binutils: binutils: heap-based buffer overflow in finish_stab in stabs.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affect
http://www.securityfocus.com/bid/104540https://bugs.launchpad.net/ubuntu/+source/binutils/+bug/1763102https://gcc.gnu.org/bugzilla/show_bug.cgi?id=85454https://security.gentoo.org/glsa/201908-01https://sourceware.org/bugzilla/show_bug.cgi?id=23057https://usn.ubuntu.com/4336-1/http://www.securityfocus.com/bid/104540https://bugs.launchpad.net/ubuntu/+source/binutils/+bug/1763102https://gcc.gnu.org/bugzilla/show_bug.cgi?id=85454https://security.gentoo.org/glsa/201908-01https://sourceware.org/bugzilla/show_bug.cgi?id=23057https://usn.ubuntu.com/4336-1/
2018-06-23
Published