CVE-2020-19726
published 2023-08-22CVE-2020-19726: An issue was discovered in binutils libbfd.c 2.36 relating to the auxiliary symbol data allows attackers to read or write to system memory or cause a denial of…
PriorityP336high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.66%
47.7th percentile
An issue was discovered in binutils libbfd.c 2.36 relating to the auxiliary symbol data allows attackers to read or write to system memory or cause a denial of service.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | binutils | < binutils 2.37-3 (bookworm) | binutils 2.37-3 (bookworm) |
| gnu | binutils | — | — |
| gnu | binutils | >= 0 < 2.37-3 | 2.37-3 |
| gnu | binutils | >= 0 < 2.37-3 | 2.37-3 |
| gnu | binutils | >= 0 < 2.37-3 | 2.37-3 |
| gnu | binutils | >= 0 < 2.34-6ubuntu1.7 | 2.34-6ubuntu1.7 |
| gnu | binutils | >= 0 < 2.38-4ubuntu2.4 | 2.38-4ubuntu2.4 |
| gnu | binutils | >= 0 < 2.24-5ubuntu14.2+esm3 | 2.24-5ubuntu14.2+esm3 |
| gnu | binutils | >= 0 < 2.24-5ubuntu14.2+esm6 | 2.24-5ubuntu14.2+esm6 |
| gnu | binutils | >= 0 < 2.26.1-1ubuntu1~16.04.8+esm7 | 2.26.1-1ubuntu1~16.04.8+esm7 |
| gnu | binutils | >= 0 < 2.30-21ubuntu1~18.04.9+esm1 | 2.30-21ubuntu1~18.04.9+esm1 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8LOW
vendor_redhat8.8HIGH
vendor_ubuntu8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
GNU binutils vulnerabilities
vendor_ubuntu·2023-12-11·CVSS 8.8
CVE-2022-35205 [HIGH] GNU binutils vulnerabilities
Title: GNU binutils vulnerabilities
Summary: Several security issues were fixed in GNU binutils.
It was discovered that GNU binutils incorrectly handled certain COFF files.
An attacker could possibly use this issue to cause a crash or execute
arbitrary code. This issue only affected Ubuntu 14.04 LTS. (CVE-2022-38533)
It was discovered that GNU binutils was not properly performing bounds
checks in several functions, which could lead to a buffer overflow. An
attacker could possibly use this issue to cause a denial of service,
expose sensitive information or execute arbitrary code. This issue only
affected Ubuntu 20.04 LTS and Ubuntu 22.04 LTS.
(CVE-2022-4285, CVE-2020-19726, CVE-2021-46174)
It was discovered that GNU binutils contained a reachable assertion, which
could lead to an intent
Ubuntu
GNU binutils vulnerabilities
vendor_ubuntu·2023-09-18·CVSS 5.5
CVE-2020-19726 [MEDIUM] GNU binutils vulnerabilities
Title: GNU binutils vulnerabilities
Summary: Several security issues were fixed in GNU binutils.
It was discovered that a memory leak existed in certain GNU binutils
modules. An attacker could possibly use this issue to cause a denial of
service (memory exhaustion). (CVE-2020-19724, CVE-2020-21490)
It was discovered that GNU binutils was not properly performing bounds
checks in several functions, which could lead to a buffer overflow. An
attacker could possibly use this issue to cause a denial of service,
expose sensitive information or execute arbitrary code.
(CVE-2020-19726, CVE-2021-46174, CVE-2022-45703)
It was discovered that GNU binutils was not properly initializing heap
memory when processing certain print instructions. An attacker could
possibly use this issue to expose sensit
Red Hat
binutils: heap-based buffer overflow in bfd_getl32() in bfd/libbfd.c
vendor_redhat·2023-07-14·CVSS 8.8
CVE-2020-19726 [HIGH] binutils: heap-based buffer overflow in bfd_getl32() in bfd/libbfd.c
binutils: heap-based buffer overflow in bfd_getl32() in bfd/libbfd.c
An issue was discovered in binutils libbfd.c 2.36 relating to the auxiliary symbol data allows attackers to read or write to system memory or cause a denial of service.
A heap-based buffer overflow was found in binutils in the bfd_getl32() function, relating to the auxiliary symbol data. This flaw allows an attacker to read or write to system memory or cause a denial of service.
Package: binutils (Red Hat Enterprise Linux 6) - Not affected
Package: binutils (Red Hat Enterprise Linux 7) - Not affected
Package: gdb (Red Hat Enterprise Linux 7) - Not affected
Package: binutils (Red Hat Enterprise Linux 8) - Not affected
Package: gcc-toolset-11-binutils (Red Hat Enterprise Linux 8) - Not affected
Package: gcc-toolset-
Debian
CVE-2020-19726: binutils - An issue was discovered in binutils libbfd.c 2.36 relating to the auxiliary symb...
vendor_debian·2020·CVSS 8.8
CVE-2020-19726 [HIGH] CVE-2020-19726: binutils - An issue was discovered in binutils libbfd.c 2.36 relating to the auxiliary symb...
An issue was discovered in binutils libbfd.c 2.36 relating to the auxiliary symbol data allows attackers to read or write to system memory or cause a denial of service.
Scope: local
bookworm: resolved (fixed in 2.37-3)
bullseye: open
forky: resolved (fixed in 2.37-3)
sid: resolved (fixed in 2.37-3)
trixie: resolved (fixed in 2.37-3)
OSV
binutils vulnerabilities
osv·2023-12-11·CVSS 8.8
CVE-2022-38533 [HIGH] binutils vulnerabilities
binutils vulnerabilities
It was discovered that GNU binutils incorrectly handled certain COFF files.
An attacker could possibly use this issue to cause a crash or execute
arbitrary code. This issue only affected Ubuntu 14.04 LTS. (CVE-2022-38533)
It was discovered that GNU binutils was not properly performing bounds
checks in several functions, which could lead to a buffer overflow. An
attacker could possibly use this issue to cause a denial of service,
expose sensitive information or execute arbitrary code. This issue only
affected Ubuntu 20.04 LTS and Ubuntu 22.04 LTS.
(CVE-2022-4285, CVE-2020-19726, CVE-2021-46174)
It was discovered that GNU binutils contained a reachable assertion, which
could lead to an intentional assertion failure when processing certain
crafted DWARF files. An a
OSV
binutils vulnerabilities
osv·2023-09-18·CVSS 5.5
CVE-2020-19724 [MEDIUM] binutils vulnerabilities
binutils vulnerabilities
It was discovered that a memory leak existed in certain GNU binutils
modules. An attacker could possibly use this issue to cause a denial of
service (memory exhaustion). (CVE-2020-19724, CVE-2020-21490)
It was discovered that GNU binutils was not properly performing bounds
checks in several functions, which could lead to a buffer overflow. An
attacker could possibly use this issue to cause a denial of service,
expose sensitive information or execute arbitrary code.
(CVE-2020-19726, CVE-2021-46174, CVE-2022-45703)
It was discovered that GNU binutils was not properly initializing heap
memory when processing certain print instructions. An attacker could
possibly use this issue to expose sensitive information. (CVE-2020-35342)
It was discovered that GNU binutils wa
GHSA
GHSA-r7qv-f5p4-f3qr: An issue was discovered in binutils libbfd
ghsa_unreviewed·2023-08-22
CVE-2020-19726 [HIGH] CWE-400 GHSA-r7qv-f5p4-f3qr: An issue was discovered in binutils libbfd
An issue was discovered in binutils libbfd.c 2.36 relating to the auxiliary symbol data allows attackers to read or write to system memory or cause a denial of service.
OSV
CVE-2020-19726: An issue was discovered in binutils libbfd
osv·2023-08-22·CVSS 8.8
CVE-2020-19726 [HIGH] CVE-2020-19726: An issue was discovered in binutils libbfd
An issue was discovered in binutils libbfd.c 2.36 relating to the auxiliary symbol data allows attackers to read or write to system memory or cause a denial of service.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-08-22
Published