CVE-2018-17360
published 2018-09-23CVE-2018-17360: An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. a heap-based buffer over-read in…
PriorityP419medium5.5CVSS 3.0
AVLACLPRNUIRSUCNINAH
EPSS
1.34%
68.4th percentile
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. a heap-based buffer over-read in bfd_getl32 in libbfd.c allows an attacker to cause a denial of service through a crafted PE file. This vulnerability can be triggered by the executable objdump.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | binutils | < binutils 2.32.51.20190707-1 (bookworm) | binutils 2.32.51.20190707-1 (bookworm) |
| gnu | binutils | — | — |
| gnu | binutils | >= 0 < 2.32.51.20190707-1 | 2.32.51.20190707-1 |
| gnu | binutils | >= 0 < 2.32.51.20190707-1 | 2.32.51.20190707-1 |
| gnu | binutils | >= 0 < 2.32.51.20190707-1 | 2.32.51.20190707-1 |
| gnu | binutils | >= 0 < 2.32.51.20190707-1 | 2.32.51.20190707-1 |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r424-xhv9-jprm: An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2
ghsa_unreviewed·2022-05-13
CVE-2018-17360 [MEDIUM] CWE-125 GHSA-r424-xhv9-jprm: An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. a heap-based buffer over-read in bfd_getl32 in libbfd.c allows an attacker to cause a denial of service through a crafted PE file. This vulnerability can be triggered by the executable objdump.
OSV
CVE-2018-17360: An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2
osv·2018-09-23·CVSS 5.5
CVE-2018-17360 [MEDIUM] CVE-2018-17360: An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. a heap-based buffer over-read in bfd_getl32 in libbfd.c allows an attacker to cause a denial of service through a crafted PE file. This vulnerability can be triggered by the executable objdump.
Ubuntu
GNU binutils vulnerabilities
vendor_ubuntu·2021-07-21
CVE-2018-19932 GNU binutils vulnerabilities
Title: GNU binutils vulnerabilities
Summary: Several security issues were fixed in GNU binutils.
USN-4336-1 fixed several vulnerabilities in GNU binutils. This update provides
the corresponding update for Ubuntu 16.04 ESM.
Original advisory details:
It was discovered that GNU binutils contained a large number of security
issues. If a user or automated system were tricked into processing a
specially-crafted file, a remote attacker could cause GNU binutils to
crash, resulting in a denial of service, or possibly execute arbitrary
code.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
GNU binutils vulnerabilities
vendor_ubuntu·2020-04-22
CVE-2018-1000876 GNU binutils vulnerabilities
Title: GNU binutils vulnerabilities
Summary: Several security issues were fixed in GNU binutils.
It was discovered that GNU binutils contained a large number of security
issues. If a user or automated system were tricked into processing a
specially-crafted file, a remote attacker could cause GNU binutils to
crash, resulting in a denial of service, or possibly execute arbitrary
code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
binutils: heap-based buffer over-read in bfd_getl32 in libbfd.c
vendor_redhat·2018-09-19·CVSS 5.5
CVE-2018-17360 [MEDIUM] CWE-119 binutils: heap-based buffer over-read in bfd_getl32 in libbfd.c
binutils: heap-based buffer over-read in bfd_getl32 in libbfd.c
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. a heap-based buffer over-read in bfd_getl32 in libbfd.c allows an attacker to cause a denial of service through a crafted PE file. This vulnerability can be triggered by the executable objdump.
Statement: This issue is classified with a low severity primarily because binutils is not typically exposed to untrusted inputs in most environments, limiting the possibility of exploitation. Additionally, this heap-based buffer over-read is only triggered during the parsing of a specially crafted file, requiring an attacker to convince a user to process this file with objdump. Furthermore, binutils does not handle pr
Debian
CVE-2018-17360: binutils - An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd)...
vendor_debian·2018·CVSS 5.5
CVE-2018-17360 [MEDIUM] CVE-2018-17360: binutils - An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd)...
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. a heap-based buffer over-read in bfd_getl32 in libbfd.c allows an attacker to cause a denial of service through a crafted PE file. This vulnerability can be triggered by the executable objdump.
Scope: local
bookworm: resolved (fixed in 2.32.51.20190707-1)
bullseye: resolved (fixed in 2.32.51.20190707-1)
forky: resolved (fixed in 2.32.51.20190707-1)
sid: resolved (fixed in 2.32.51.20190707-1)
trixie: resolved (fixed in 2.32.51.20190707-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-17360 mingw-binutils: binutils: heap-based buffer over-read in bfd_getl32 in libbfd.c [fedora-all]
bugzilla·2018-09-25·CVSS 5.5
CVE-2018-17360 [MEDIUM] CVE-2018-17360 mingw-binutils: binutils: heap-based buffer over-read in bfd_getl32 in libbfd.c [fedora-all]
CVE-2018-17360 mingw-binutils: binutils: heap-based buffer over-read in bfd_getl32 in libbfd.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affec
Bugzilla
CVE-2018-17360 binutils: heap-based buffer over-read in bfd_getl32 in libbfd.c
bugzilla·2018-09-25·CVSS 5.5
CVE-2018-17360 [MEDIUM] CVE-2018-17360 binutils: heap-based buffer over-read in bfd_getl32 in libbfd.c
CVE-2018-17360 binutils: heap-based buffer over-read in bfd_getl32 in libbfd.c
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. a heap-based buffer over-read in bfd_getl32 in libbfd.c allows an attacker to cause a denial of service through a crafted PE file. This vulnerability can be triggered by the executable objdump.
References:
https://sourceware.org/bugzilla/show_bug.cgi?id=23685
Upstream Patch:
https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=cf93e9c2cf8f8b2566f8fc86e961592b51b5980d
Discussion:
Created binutils tracking bugs for this issue:
Affects: fedora-all [bug 1632924]
Created mingw-binutils tracking bugs for this issue:
Affects: epel-all [bug 1632923]
Affects: fedora-all [bug 1632927]
Bugzilla
CVE-2018-17360 binutils: heap-based buffer over-read in bfd_getl32 in libbfd.c [fedora-all]
bugzilla·2018-09-25·CVSS 5.5
CVE-2018-17360 [MEDIUM] CVE-2018-17360 binutils: heap-based buffer over-read in bfd_getl32 in libbfd.c [fedora-all]
CVE-2018-17360 binutils: heap-based buffer over-read in bfd_getl32 in libbfd.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supp
Bugzilla
CVE-2018-17360 mingw-binutils: binutils: heap-based buffer over-read in bfd_getl32 in libbfd.c [epel-all]
bugzilla·2018-09-25·CVSS 5.5
CVE-2018-17360 [MEDIUM] CVE-2018-17360 mingw-binutils: binutils: heap-based buffer over-read in bfd_getl32 in libbfd.c [epel-all]
CVE-2018-17360 mingw-binutils: binutils: heap-based buffer over-read in bfd_getl32 in libbfd.c [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects m
arXiv
Fuzzing: Randomness? Reasoning! Efficient Directed Fuzzing via Large Language Models
arxiv_fulltext·2025-06-30
Fuzzing: Randomness? Reasoning! Efficient Directed Fuzzing via Large Language Models
Large Language Model Assisted Directed Fuzzing:\ First, Then Fuzzing
Fuzzing: Randomness? Reasoning! \ Directed Fuzzing via Large Language Models
Xiaotao Feng
360 Security Technology Inc.
Beijing, China
[email protected]
Xiaogang Zhu
School of Computer and Mathematical Sciences
The University of Adelaide
Adelaide, SA, Australia
[email protected]
Kun Hu
School of Science
Edith Cowan University
Joondalup, WA, Australia
[email protected]
Jincheng Wang
360 Security Technology Inc.
Beijing, China
[email protected]
Yingjie Cao
360 Security Technology Inc.
Beijing, China
[email protected]
Guang Gong
360 Security Technology Inc.
Beijing, China
[email protected]
Jianfeng Pan
360 Security Technology Inc.
Beijing, China
[email protected]
## Abstrac
http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00072.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-11/msg00008.htmlhttps://sourceware.org/bugzilla/show_bug.cgi?id=23685https://usn.ubuntu.com/4336-1/http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00072.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-11/msg00008.htmlhttps://sourceware.org/bugzilla/show_bug.cgi?id=23685https://usn.ubuntu.com/4336-1/
2018-09-23
Published