cbcvebase.
CVE-2019-17451
published 2019-10-10

CVE-2019-17451: An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is an integer overflow leading to a…

medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is an integer overflow leading to a SEGV in _bfd_dwarf2_find_nearest_line in dwarf2.c, as demonstrated by nm.

Affected

12 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
debianbinutils< binutils 2.34-1 (bookworm)binutils 2.34-1 (bookworm)
gnubinutils
gnubinutils>= 0 < 2.34-12.34-1
gnubinutils>= 0 < 2.34-12.34-1
gnubinutils>= 0 < 2.34-12.34-1
gnubinutils>= 0 < 2.34-12.34-1
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccm1_binutils_2.32-4_on_cbl_mariner_1.0
opensuseleap
opensuseleap

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv6.5MEDIUM