CVE-2018-20671
published 2019-01-04CVE-2018-20671: load_specific_debug_section in objdump.c in GNU Binutils through 2.31.1 contains an integer overflow vulnerability that can trigger a heap-based buffer…
PriorityP422medium5.5CVSS 3.0
AVLACLPRNUIRSUCNINAH
EPSS
1.97%
79.0th percentile
load_specific_debug_section in objdump.c in GNU Binutils through 2.31.1 contains an integer overflow vulnerability that can trigger a heap-based buffer overflow via a crafted section size.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | binutils | < binutils 2.32.51.20190707-1 (bookworm) | binutils 2.32.51.20190707-1 (bookworm) |
| gnu | binutils | <= 2.31.1 | — |
| gnu | binutils | >= 0 < 2.32.51.20190707-1 | 2.32.51.20190707-1 |
| gnu | binutils | >= 0 < 2.32.51.20190707-1 | 2.32.51.20190707-1 |
| gnu | binutils | >= 0 < 2.32.51.20190707-1 | 2.32.51.20190707-1 |
| gnu | binutils | >= 0 < 2.32.51.20190707-1 | 2.32.51.20190707-1 |
| gnu | binutils | >= 0 < 2.24-5ubuntu14.2+esm5 | 2.24-5ubuntu14.2+esm5 |
| gnu | binutils | >= 0 < 2.26.1-1ubuntu1~16.04.8+esm9 | 2.26.1-1ubuntu1~16.04.8+esm9 |
| gnu | binutils | >= 0 < 2.30-21ubuntu1~18.04.9+esm3 | 2.30-21ubuntu1~18.04.9+esm3 |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
GNU binutils vulnerabilities
vendor_ubuntu·2023-10-04·CVSS 7.8
CVE-2022-35205 [HIGH] GNU binutils vulnerabilities
Title: GNU binutils vulnerabilities
Summary: Several security issues were fixed in GNU binutils.
It was discovered that GNU binutils was not properly performing checks
when dealing with memory allocation operations, which could lead to
excessive memory consumption. An attacker could possibly use this issue
to cause a denial of service. This issue only affected Ubuntu 14.04 LTS.
(CVE-2017-17122, CVE-2017-8421)
It was discovered that GNU binutils was not properly performing bounds
checks when processing debug sections with objdump, which could lead to
an overflow. An attacker could possibly use this issue to cause a denial
of service or execute arbitrary code. This issue only affected Ubuntu
14.04 LTS. (CVE-2018-20671, CVE-2018-6543)
It was discovered that GNU binutils contained a reacha
Ubuntu
GNU binutils vulnerabilities
vendor_ubuntu·2021-07-21
CVE-2018-19932 GNU binutils vulnerabilities
Title: GNU binutils vulnerabilities
Summary: Several security issues were fixed in GNU binutils.
USN-4336-1 fixed several vulnerabilities in GNU binutils. This update provides
the corresponding update for Ubuntu 16.04 ESM.
Original advisory details:
It was discovered that GNU binutils contained a large number of security
issues. If a user or automated system were tricked into processing a
specially-crafted file, a remote attacker could cause GNU binutils to
crash, resulting in a denial of service, or possibly execute arbitrary
code.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
GNU binutils vulnerabilities
vendor_ubuntu·2020-04-22
CVE-2018-1000876 GNU binutils vulnerabilities
Title: GNU binutils vulnerabilities
Summary: Several security issues were fixed in GNU binutils.
It was discovered that GNU binutils contained a large number of security
issues. If a user or automated system were tricked into processing a
specially-crafted file, a remote attacker could cause GNU binutils to
crash, resulting in a denial of service, or possibly execute arbitrary
code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
binutils: Integer overflow in load_specific_debug_section function
vendor_redhat·2018-12-19·CVSS 5.5
CVE-2018-20671 [MEDIUM] CWE-190 binutils: Integer overflow in load_specific_debug_section function
binutils: Integer overflow in load_specific_debug_section function
load_specific_debug_section in objdump.c in GNU Binutils through 2.31.1 contains an integer overflow vulnerability that can trigger a heap-based buffer overflow via a crafted section size.
Statement: This issue did not affect the versions of binutils as shipped with Red Hat Enterprise Linux 5, 6, and 7 as they did not include the vulnerable code. Moreover the flaw can only be triggered on 32bit versions of the component.
Package: binutils (Red Hat Enterprise Linux 5) - Not affected
Package: binutils (Red Hat Enterprise Linux 6) - Not affected
Package: binutils (Red Hat Enterprise Linux 7) - Not affected
Package: binutils (Red Hat Enterprise Linux 8) - Will not fix
Package: mingw-binutils (Red Hat Enterprise Linux 8)
Debian
CVE-2018-20671: binutils - load_specific_debug_section in objdump.c in GNU Binutils through 2.31.1 contains...
vendor_debian·2018·CVSS 5.5
CVE-2018-20671 [MEDIUM] CVE-2018-20671: binutils - load_specific_debug_section in objdump.c in GNU Binutils through 2.31.1 contains...
load_specific_debug_section in objdump.c in GNU Binutils through 2.31.1 contains an integer overflow vulnerability that can trigger a heap-based buffer overflow via a crafted section size.
Scope: local
bookworm: resolved (fixed in 2.32.51.20190707-1)
bullseye: resolved (fixed in 2.32.51.20190707-1)
forky: resolved (fixed in 2.32.51.20190707-1)
sid: resolved (fixed in 2.32.51.20190707-1)
trixie: resolved (fixed in 2.32.51.20190707-1)
OSV
binutils vulnerabilities
osv·2023-10-04·CVSS 7.8
CVE-2017-17122 [HIGH] binutils vulnerabilities
binutils vulnerabilities
It was discovered that GNU binutils was not properly performing checks
when dealing with memory allocation operations, which could lead to
excessive memory consumption. An attacker could possibly use this issue
to cause a denial of service. This issue only affected Ubuntu 14.04 LTS.
(CVE-2017-17122, CVE-2017-8421)
It was discovered that GNU binutils was not properly performing bounds
checks when processing debug sections with objdump, which could lead to
an overflow. An attacker could possibly use this issue to cause a denial
of service or execute arbitrary code. This issue only affected Ubuntu
14.04 LTS. (CVE-2018-20671, CVE-2018-6543)
It was discovered that GNU binutils contained a reachable assertion, which
could lead to an intentional assertion failure when
GHSA
GHSA-crr7-7j5m-9cvf: load_specific_debug_section in objdump
ghsa_unreviewed·2022-05-13
CVE-2018-20671 [MEDIUM] CWE-787 GHSA-crr7-7j5m-9cvf: load_specific_debug_section in objdump
load_specific_debug_section in objdump.c in GNU Binutils through 2.31.1 contains an integer overflow vulnerability that can trigger a heap-based buffer overflow via a crafted section size.
OSV
CVE-2018-20671: load_specific_debug_section in objdump
osv·2019-01-04·CVSS 5.5
CVE-2018-20671 [MEDIUM] CVE-2018-20671: load_specific_debug_section in objdump
load_specific_debug_section in objdump.c in GNU Binutils through 2.31.1 contains an integer overflow vulnerability that can trigger a heap-based buffer overflow via a crafted section size.
No detection rules found.
No public exploits indexed.
arXiv
Multiple Targets Directed Greybox Fuzzing
arxiv_fulltext·2022-06-30
Multiple Targets Directed Greybox Fuzzing
Multiple Targets Directed Greybox Fuzzing
Hongliang Liang, Xianglin Cheng, Jie Liu, Jin Li
H. Liang, X. Cheng, J. Liu are with Trusted Software and Intelligent System Lab, Beijing University of Posts and Telecommunications, Beijing, China. E-mail: \hliang, chengxl, liujie_ran\@bupt.edu.cn.
J. Li is with Nation Key Laboratory of Science and Technology on Information System Security, Beijing, China. E-mail: [email protected].
This research is partially supported by CNKLSTISS.
## Abstract
Directed greybox fuzzing (DGF) can quickly discover or reproduce bugs in programs by seeking to reach a program location or explore some locations in order. However, due to their static stage division and coarse-grained energy scheduling, prior DGF tools perform poorly when facing multiple target locat
Bugzilla
CVE-2018-20671 binutils: Integer overflow in load_specific_debug_section function
bugzilla·2019-01-09·CVSS 5.5
CVE-2018-20671 [MEDIUM] CVE-2018-20671 binutils: Integer overflow in load_specific_debug_section function
CVE-2018-20671 binutils: Integer overflow in load_specific_debug_section function
An integer overflow was found in load_specific_debug_section function.
Upstream issue:
https://sourceware.org/bugzilla/show_bug.cgi?id=24005
Upstream patch:
https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=11fa9f134fd658075c6f74499c780df045d9e9ca
Discussion:
Created binutils tracking bugs for this issue:
Affects: fedora-all [bug 1664713]
Created mingw-binutils tracking bugs for this issue:
Affects: epel-all [bug 1664715]
Affects: fedora-all [bug 1664714]
---
When binutils is compiled in 32bit mode, an integer overflow is possible in load_specific_debug_section function() in objdump.c which may lead to an heap-based buffer overflow in bfd_get_full_section_contents().
---
Statement:
Th
Bugzilla
CVE-2018-1000876 CVE-2018-20623 CVE-2018-20651 CVE-2018-20657 CVE-2018-20671 CVE-2018-20673 binutils: various flaws [fedora-all]
bugzilla·2019-01-09·CVSS 7.8
CVE-2018-1000876 [HIGH] CVE-2018-1000876 CVE-2018-20623 CVE-2018-20651 CVE-2018-20657 CVE-2018-20671 CVE-2018-20673 binutils: various flaws [fedora-all]
CVE-2018-1000876 CVE-2018-20623 CVE-2018-20651 CVE-2018-20657 CVE-2018-20671 CVE-2018-20673 binutils: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
N
Bugzilla
CVE-2018-1000876 CVE-2018-20623 CVE-2018-20651 CVE-2018-20657 CVE-2018-20671 CVE-2018-20673 mingw-binutils: various flaws [epel-all]
bugzilla·2019-01-09·CVSS 7.8
CVE-2018-1000876 [HIGH] CVE-2018-1000876 CVE-2018-20623 CVE-2018-20651 CVE-2018-20657 CVE-2018-20671 CVE-2018-20673 mingw-binutils: various flaws [epel-all]
CVE-2018-1000876 CVE-2018-20623 CVE-2018-20651 CVE-2018-20657 CVE-2018-20671 CVE-2018-20673 mingw-binutils: various flaws [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Bugzilla
CVE-2018-1000876 CVE-2018-20623 CVE-2018-20651 CVE-2018-20657 CVE-2018-20671 CVE-2018-20673 mingw-binutils: various flaws [fedora-all]
bugzilla·2019-01-09·CVSS 7.8
CVE-2018-1000876 [HIGH] CVE-2018-1000876 CVE-2018-20623 CVE-2018-20651 CVE-2018-20657 CVE-2018-20671 CVE-2018-20673 mingw-binutils: various flaws [fedora-all]
CVE-2018-1000876 CVE-2018-20623 CVE-2018-20651 CVE-2018-20657 CVE-2018-20671 CVE-2018-20673 mingw-binutils: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit messa
http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00072.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-11/msg00008.htmlhttp://www.securityfocus.com/bid/106457https://sourceware.org/bugzilla/show_bug.cgi?id=24005https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git%3Bh=11fa9f134fd658075c6f74499c780df045d9e9cahttps://usn.ubuntu.com/4336-1/http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00072.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-11/msg00008.htmlhttp://www.securityfocus.com/bid/106457https://sourceware.org/bugzilla/show_bug.cgi?id=24005https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git%3Bh=11fa9f134fd658075c6f74499c780df045d9e9cahttps://usn.ubuntu.com/4336-1/
2019-01-04
Published