Severity
5.5MEDIUMNVD
EPSS
0.1%
top 65.45%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 23
Latest updateMay 24

Description

GNU binutils gold gold v1.11-v1.16 (GNU binutils v2.21-v2.31.1) is affected by: Improper Input Validation, Signed/Unsigned Comparison, Out-of-bounds Read. The impact is: Denial of service. The component is: gold/fileread.cc:497, elfcpp/elfcpp_file.h:644. The attack vector is: An ELF file with an invalid e_shoff header field must be opened.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages4 packages

NVDgnu/binutils_gold1.111.16
CVEListV5gnu_binutils/goldgold v1.11-v1.16 (GNU binutils v2.21-v2.31.1)
Debiangnu/binutils< 2.38.50.20220627-1+2
NVDgnu/binutils2.212.31.1

🔴Vulnerability Details

3
GHSA
GHSA-r3p5-p24x-hqxq: GNU binutils gold gold v12022-05-24
CVEList
CVE-2019-1010204: GNU binutils gold gold v12019-07-23
OSV
CVE-2019-1010204: GNU binutils gold gold v12019-07-23

📋Vendor Advisories

3
Ubuntu
GNU binutils vulnerability2022-03-28
Red Hat
binutils: Improper Input Validation, Signed/Unsigned Comparison, Out-of-bounds Read in gold/fileread.cc and elfcpp/elfcpp_file.h leads to denial of service2019-07-24
Debian
CVE-2019-1010204: binutils - GNU binutils gold gold v1.11-v1.16 (GNU binutils v2.21-v2.31.1) is affected by: ...2019

💬Community

2
Bugzilla
CVE-2019-1010204 binutils: Improper Input Validation, Signed/Unsigned Comparison, Out-of-bounds Read in gold/fileread.cc and elfcpp/elfcpp_file.h leads to denial of service2019-08-01
Bugzilla
CVE-2019-1010204 binutils: Improper Input Validation, Signed/Unsigned Comparison, Out-of-bounds Read in gold/fileread.cc and elfcpp/elfcpp_file.h leads to denial of service [fedora-all]2019-08-01
CVE-2019-1010204 — Out-of-bounds Read in GNU Binutils | cvebase