cbcvebase.
CVE-2019-17451
published 2019-10-10

CVE-2019-17451: An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is an integer overflow leading to a…

PriorityP428medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
2.40%
82.3th percentile
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is an integer overflow leading to a SEGV in _bfd_dwarf2_find_nearest_line in dwarf2.c, as demonstrated by nm.

Affected

12 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
debianbinutils< binutils 2.34-1 (bookworm)binutils 2.34-1 (bookworm)
gnubinutils
gnubinutils>= 0 < 2.34-12.34-1
gnubinutils>= 0 < 2.34-12.34-1
gnubinutils>= 0 < 2.34-12.34-1
gnubinutils>= 0 < 2.34-12.34-1
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccm1_binutils_2.32-4_on_cbl_mariner_1.0
opensuseleap
opensuseleap

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5LOW
vendor_msrc6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.