CVE-2023-1579
published 2023-04-03CVE-2023-1579: Heap based buffer overflow in binutils-gdb/bfd/libbfd.c in bfd_getl64.
PriorityP334high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.49%
38.8th percentile
Heap based buffer overflow in binutils-gdb/bfd/libbfd.c in bfd_getl64.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | binutils | < binutils 2.40-2 (bookworm) | binutils 2.40-2 (bookworm) |
| gnu | binutils | — | — |
| gnu | binutils | — | — |
| gnu | binutils | >= 0 < 2.40-2 | 2.40-2 |
| gnu | binutils | >= 0 < 2.40-2 | 2.40-2 |
| gnu | binutils | >= 0 < 2.40-2 | 2.40-2 |
| gnu | binutils | >= 0 < 2.30-21ubuntu1~18.04.9 | 2.30-21ubuntu1~18.04.9 |
| gnu | binutils | >= 0 < 2.34-6ubuntu1.5 | 2.34-6ubuntu1.5 |
| gnu | binutils | >= 0 < 2.38-4ubuntu2.2 | 2.38-4ubuntu2.2 |
| gnu | binutils | >= 0 < 2.24-5ubuntu14.2+esm1 | 2.24-5ubuntu14.2+esm1 |
| gnu | binutils | >= 0 < 2.26.1-1ubuntu1~16.04.8+esm6 | 2.26.1-1ubuntu1~16.04.8+esm6 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8LOW
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
binutils vulnerabilities
osv·2023-05-24·CVSS 7.8
CVE-2023-1579 [HIGH] binutils vulnerabilities
binutils vulnerabilities
It was discovered that GNU binutils incorrectly handled certain DWARF
files. An attacker could possibly use this issue to cause a crash or
execute arbitrary code. This issue only affected Ubuntu 22.10.
(CVE-2023-1579)
It was discovered that GNU binutils did not properly verify the version
definitions in zer0-lengthverdef table. An attacker could possibly use this
issue to cause a crash or execute arbitrary code. This issue only affected
Ubuntu 22.04 LTS, Ubuntu 22.10 and Ubuntu 23.04. (CVE-2023-1972)
It was discovered that GNU binutils did not properly validate the size of
length parameter in vms-alpha. An attacker could possibly use this issue to
cause a crash or access sensitive information. This issue only affected
Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 2
GHSA
GHSA-7p63-jgg6-rgpv: Heap based buffer overflow in binutils-gdb/bfd/libbfd
ghsa_unreviewed·2023-04-04
CVE-2023-1579 [HIGH] CWE-119 GHSA-7p63-jgg6-rgpv: Heap based buffer overflow in binutils-gdb/bfd/libbfd
Heap based buffer overflow in binutils-gdb/bfd/libbfd.c in bfd_getl64.
OSV
CVE-2023-1579: Heap based buffer overflow in binutils-gdb/bfd/libbfd
osv·2023-04-03·CVSS 7.8
CVE-2023-1579 [HIGH] CVE-2023-1579: Heap based buffer overflow in binutils-gdb/bfd/libbfd
Heap based buffer overflow in binutils-gdb/bfd/libbfd.c in bfd_getl64.
Ubuntu
GNU binutils vulnerabilities
vendor_ubuntu·2023-05-24·CVSS 7.8
CVE-2023-1972 [HIGH] GNU binutils vulnerabilities
Title: GNU binutils vulnerabilities
Summary: Several security issues were fixed in GNU binutils.
It was discovered that GNU binutils incorrectly handled certain DWARF
files. An attacker could possibly use this issue to cause a crash or
execute arbitrary code. This issue only affected Ubuntu 22.10.
(CVE-2023-1579)
It was discovered that GNU binutils did not properly verify the version
definitions in zer0-lengthverdef table. An attacker could possibly use this
issue to cause a crash or execute arbitrary code. This issue only affected
Ubuntu 22.04 LTS, Ubuntu 22.10 and Ubuntu 23.04. (CVE-2023-1972)
It was discovered that GNU binutils did not properly validate the size of
length parameter in vms-alpha. An attacker could possibly use this issue to
cause a crash or access sensitive informati
Red Hat
binutils: Heap-buffer-overflow binutils-gdb/bfd/libbfd.c in bfd_getl64
vendor_redhat·2023-01-11·CVSS 7.8
CVE-2023-1579 [HIGH] CWE-787 binutils: Heap-buffer-overflow binutils-gdb/bfd/libbfd.c in bfd_getl64
binutils: Heap-buffer-overflow binutils-gdb/bfd/libbfd.c in bfd_getl64
Heap based buffer overflow in binutils-gdb/bfd/libbfd.c in bfd_getl64.
A heap based buffer overflow was found in binutils-gdb/bfd/libbfd.c in bfd_getl64 in binutils.
Statement: Because this vulnerability requires that an unsuspecting user uses binutils-gdb to analyze a specially crafted malicious DWARF file, and because the consequences of the memory corruption caused by the flaw are limited to the privileges of the user who analyzes the malicious file, Red Hat assesses this vulnerability's impact as Moderate.
Package: binutils (Red Hat Enterprise Linux 6) - Out of support scope
Package: binutils (Red Hat Enterprise Linux 7) - Out of support scope
Package: gdb (Red Hat Enterprise Linux 7) - Out of support scope
P
Debian
CVE-2023-1579: binutils - Heap based buffer overflow in binutils-gdb/bfd/libbfd.c in bfd_getl64.
vendor_debian·2023·CVSS 7.8
CVE-2023-1579 [HIGH] CVE-2023-1579: binutils - Heap based buffer overflow in binutils-gdb/bfd/libbfd.c in bfd_getl64.
Heap based buffer overflow in binutils-gdb/bfd/libbfd.c in bfd_getl64.
Scope: local
bookworm: resolved (fixed in 2.40-2)
bullseye: open
forky: resolved (fixed in 2.40-2)
sid: resolved (fixed in 2.40-2)
trixie: resolved (fixed in 2.40-2)
No detection rules found.
No public exploits indexed.
arXiv
Top of the Heap: Efficient Memory Error Protection of Safe Heap Objects
arxiv_fulltext·2024-08-19
Top of the Heap: Efficient Memory Error Protection of Safe Heap Objects
Top of the Heap: Efficient Memory Error Protection
of Safe Heap Objects
0
@IEEEauthorhalign
@IEEEauthorhalign
Kaiming Huang
Penn State University
[email protected]
Mathias Payer
EPFL
[email protected]
Zhiyun Qian
UC Riverside
[email protected]
Jack Sampson
Penn State University
[email protected]
\ \ \ \ Gang Tan
\ \ \ \ Penn State University
\ \ \ \ [email protected]
Trent Jaeger
Penn State University
[email protected]
Kaiming Huang
Penn State University
[email protected]
Mathias Payer
EPFL
[email protected]
Zhiyun Qian
UC Riverside
[email protected]
Jack Sampson
Penn State University
[email protected]
Gang Tan
Penn State University
[email protected]
Trent Jaeger
UC Riverside
[email protected]
0
CCSXML
10002978.10003022.10003023
Security and privacy Software
Bugzilla
CVE-2023-1579 binutils: Heap-buffer-overflow binutils-gdb/bfd/libbfd.c in bfd_getl64
bugzilla·2023-03-22·CVSS 7.8
CVE-2023-1579 [HIGH] CVE-2023-1579 binutils: Heap-buffer-overflow binutils-gdb/bfd/libbfd.c in bfd_getl64
CVE-2023-1579 binutils: Heap-buffer-overflow binutils-gdb/bfd/libbfd.c in bfd_getl64
Heap based buffer overflow in binutils-gdb/bfd/libbfd.c in bfd_getl64.
References:
https://sourceware.org/bugzilla/show_bug.cgi?id=29988
Discussion:
Created binutils tracking bugs for this issue:
Affects: fedora-36 [bug 2181207]
Affects: fedora-37 [bug 2181213]
Affects: fedora-all [bug 2181203]
Created gdb tracking bugs for this issue:
Affects: fedora-36 [bug 2181208]
Created insight tracking bugs for this issue:
Affects: fedora-36 [bug 2181209]
Affects: fedora-37 [bug 2181214]
Created mingw-binutils tracking bugs for this issue:
Affects: fedora-36 [bug 2181210]
Affects: fedora-37 [bug 2181215]
Created radare2 tracking bugs for this issue:
Affects: epel-7 [bug 2181204]
Affects: epel-8 [bu
https://security.gentoo.org/glsa/202309-15https://security.netapp.com/advisory/ntap-20230511-0009/https://sourceware.org/bugzilla/show_bug.cgi?id=29988https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git%3Bh=11d171f1910b508a81d21faa087ad1af573407d8https://security.gentoo.org/glsa/202309-15https://security.netapp.com/advisory/ntap-20230511-0009/https://sourceware.org/bugzilla/show_bug.cgi?id=29988https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git%3Bh=11d171f1910b508a81d21faa087ad1af573407d8
2023-04-03
Published