CVE-2019-9075Out-of-bounds Write in Binutils

Severity
7.8HIGHNVD
EPSS
0.3%
top 49.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 24
Latest updateMay 13

Description

An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is a heap-based buffer overflow in _bfd_archive_64_bit_slurp_armap in archive64.c.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages16 packages

Debiangnu/binutils< 2.32.51.20190707-1+3
NVDgnu/binutils2.32
NVDf5/big-ip_analytics14.1.0, 15.0.0+1
NVDf5/big-ip_edge_gateway14.1.0, 15.0.0+1

Also affects: Ubuntu Linux 18.04

Patches

🔴Vulnerability Details

3
GHSA
GHSA-h4h3-65xg-3jpj: An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 22022-05-13
OSV
CVE-2019-9075: An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 22019-02-24
CVEList
CVE-2019-9075: An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 22019-02-24

📋Vendor Advisories

5
Ubuntu
GNU binutils vulnerabilities2021-07-21
Ubuntu
GNU binutils vulnerabilities2020-04-22
Red Hat
binutils: heap-based buffer overflow in function _bfd_archive_64_bit_slurp_armap in archive64.c2019-02-19
Microsoft
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd) as distributed in GNU Binutils 2.32. It is a heap-based buffer overflow in _bfd_archive_64_bit_slurp_armap in archive642019-02-12
Debian
CVE-2019-9075: binutils - An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd)...2019

💬Community

2
Bugzilla
CVE-2019-9075 binutils: heap-based buffer overflow in function _bfd_archive_64_bit_slurp_armap in archive64.c2019-02-25
Bugzilla
CVE-2019-9075 binutils: heap-based buffer overflow in function _bfd_archive_64_bit_slurp_armap in archive64.c [fedora-all]2019-02-25
CVE-2019-9075 — Out-of-bounds Write in GNU Binutils | cvebase