CVE-2019-9070Out-of-bounds Read in Binutils

Severity
7.8HIGHNVD
EPSS
0.5%
top 36.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 24
Latest updateMay 13

Description

An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. It is a heap-based buffer over-read in d_expression_1 in cp-demangle.c after many recursive calls.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages3 packages

Debiangnu/binutils< 2.32.51.20190707-1+3
NVDgnu/binutils2.32

Also affects: Ubuntu Linux 16.04, 18.04

Patches

🔴Vulnerability Details

3
GHSA
GHSA-7j27-3j2r-jhhj: An issue was discovered in GNU libiberty, as distributed in GNU Binutils 22022-05-13
CVEList
CVE-2019-9070: An issue was discovered in GNU libiberty, as distributed in GNU Binutils 22019-02-24
OSV
CVE-2019-9070: An issue was discovered in GNU libiberty, as distributed in GNU Binutils 22019-02-24

📋Vendor Advisories

6
Ubuntu
GNU binutils vulnerabilities2021-07-21
Ubuntu
GNU binutils vulnerabilities2020-04-22
Ubuntu
libiberty vulnerabilities2020-04-08
Red Hat
binutils: heap-based buffer over-read in function d_expression_1 in cp-demangle.c2019-02-18
Microsoft
An issue was discovered in GNU libiberty as distributed in GNU Binutils 2.32. It is a heap-based buffer over-read in d_expression_1 in cp-demangle.c after many recursive calls.2019-02-12

💬Community

2
Bugzilla
CVE-2019-9070 binutils: heap-based buffer over-read in function d_expression_1 in cp-demangle.c [fedora-all]2019-02-25
Bugzilla
CVE-2019-9070 binutils: heap-based buffer over-read in function d_expression_1 in cp-demangle.c2019-02-25
CVE-2019-9070 — Out-of-bounds Read in GNU Binutils | cvebase