CVE-2023-1972
published 2023-05-17CVE-2023-1972: A potential heap based buffer overflow was found in _bfd_elf_slurp_version_tables() in bfd/elf.c. This may lead to loss of availability.
PriorityP429medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
0.90%
55.8th percentile
A potential heap based buffer overflow was found in _bfd_elf_slurp_version_tables() in bfd/elf.c. This may lead to loss of availability.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | binutils | < binutils 2.41-1 (forky) | binutils 2.41-1 (forky) |
| gnu | binutils | — | — |
| gnu | binutils | >= 0 < 2.41-1 | 2.41-1 |
| gnu | binutils | >= 0 < 2.41-1 | 2.41-1 |
| gnu | binutils | >= 0 < 2.30-21ubuntu1~18.04.9 | 2.30-21ubuntu1~18.04.9 |
| gnu | binutils | >= 0 < 2.34-6ubuntu1.5 | 2.34-6ubuntu1.5 |
| gnu | binutils | >= 0 < 2.38-4ubuntu2.2 | 2.38-4ubuntu2.2 |
| gnu | binutils | >= 0 < 2.24-5ubuntu14.2+esm1 | 2.24-5ubuntu14.2+esm1 |
| gnu | binutils | >= 0 < 2.26.1-1ubuntu1~16.04.8+esm6 | 2.26.1-1ubuntu1~16.04.8+esm6 |
| gnu | binutils | 2.35 – 2.40 | — |
| gnu | gdb | >= 0 < 9.2-0ubuntu1~20.04.2 | 9.2-0ubuntu1~20.04.2 |
| gnu | gdb | >= 0 < 12.1-0ubuntu1~22.04.2 | 12.1-0ubuntu1~22.04.2 |
| gnu | gdb | >= 0 < 7.11.1-0ubuntu1~16.5+esm1 | 7.11.1-0ubuntu1~16.5+esm1 |
| gnu | gdb | >= 0 < 8.1.1-0ubuntu1+esm1 | 8.1.1-0ubuntu1+esm1 |
| msrc | cbl2_binutils_2.37-10_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian6.5LOW
vendor_msrc6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
gdb vulnerabilities
osv·2024-06-20·CVSS 5.5
CVE-2020-16599 [MEDIUM] gdb vulnerabilities
gdb vulnerabilities
It was discovered that gdb incorrectly handled certain memory operations
when parsing an ELF file. An attacker could possibly use this issue
to cause a denial of service. This issue is the result of an
incomplete fix for CVE-2020-16599. This issue only affected
Ubuntu 22.04 LTS. (CVE-2022-4285)
It was discovered that gdb incorrectly handled memory leading
to a heap based buffer overflow. An attacker could use this
issue to cause a denial of service, or possibly execute
arbitrary code. This issue only affected Ubuntu 22.04 LTS.
(CVE-2023-1972)
It was discovered that gdb incorrectly handled memory leading
to a stack overflow. An attacker could possibly use this issue
to cause a denial of service. This issue only affected
Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22
OSV
binutils vulnerabilities
osv·2023-05-24·CVSS 7.8
CVE-2023-1579 [HIGH] binutils vulnerabilities
binutils vulnerabilities
It was discovered that GNU binutils incorrectly handled certain DWARF
files. An attacker could possibly use this issue to cause a crash or
execute arbitrary code. This issue only affected Ubuntu 22.10.
(CVE-2023-1579)
It was discovered that GNU binutils did not properly verify the version
definitions in zer0-lengthverdef table. An attacker could possibly use this
issue to cause a crash or execute arbitrary code. This issue only affected
Ubuntu 22.04 LTS, Ubuntu 22.10 and Ubuntu 23.04. (CVE-2023-1972)
It was discovered that GNU binutils did not properly validate the size of
length parameter in vms-alpha. An attacker could possibly use this issue to
cause a crash or access sensitive information. This issue only affected
Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 2
GHSA
GHSA-gxpx-hfgx-m75g: A potential heap based buffer overflow was found in _bfd_elf_slurp_version_tables() in bfd/elf
ghsa_unreviewed·2023-05-18
CVE-2023-1972 [MEDIUM] CWE-119 GHSA-gxpx-hfgx-m75g: A potential heap based buffer overflow was found in _bfd_elf_slurp_version_tables() in bfd/elf
A potential heap based buffer overflow was found in _bfd_elf_slurp_version_tables() in bfd/elf.c. This may lead to loss of availability.
OSV
CVE-2023-1972: A potential heap based buffer overflow was found in _bfd_elf_slurp_version_tables() in bfd/elf
osv·2023-05-17·CVSS 6.5
CVE-2023-1972 [MEDIUM] CVE-2023-1972: A potential heap based buffer overflow was found in _bfd_elf_slurp_version_tables() in bfd/elf
A potential heap based buffer overflow was found in _bfd_elf_slurp_version_tables() in bfd/elf.c. This may lead to loss of availability.
Ubuntu
gdb vulnerabilities
vendor_ubuntu·2024-06-20·CVSS 5.5
CVE-2020-16599 [MEDIUM] gdb vulnerabilities
Title: gdb vulnerabilities
Summary: gdb could be made to crash if it opened a specially crafted file.
It was discovered that gdb incorrectly handled certain memory operations
when parsing an ELF file. An attacker could possibly use this issue
to cause a denial of service. This issue is the result of an
incomplete fix for CVE-2020-16599. This issue only affected
Ubuntu 22.04 LTS. (CVE-2022-4285)
It was discovered that gdb incorrectly handled memory leading
to a heap based buffer overflow. An attacker could use this
issue to cause a denial of service, or possibly execute
arbitrary code. This issue only affected Ubuntu 22.04 LTS.
(CVE-2023-1972)
It was discovered that gdb incorrectly handled memory leading
to a stack overflow. An attacker could possibly use this issue
to cause a denial of
Ubuntu
GNU binutils vulnerabilities
vendor_ubuntu·2023-05-24·CVSS 7.8
CVE-2023-1972 [HIGH] GNU binutils vulnerabilities
Title: GNU binutils vulnerabilities
Summary: Several security issues were fixed in GNU binutils.
It was discovered that GNU binutils incorrectly handled certain DWARF
files. An attacker could possibly use this issue to cause a crash or
execute arbitrary code. This issue only affected Ubuntu 22.10.
(CVE-2023-1579)
It was discovered that GNU binutils did not properly verify the version
definitions in zer0-lengthverdef table. An attacker could possibly use this
issue to cause a crash or execute arbitrary code. This issue only affected
Ubuntu 22.04 LTS, Ubuntu 22.10 and Ubuntu 23.04. (CVE-2023-1972)
It was discovered that GNU binutils did not properly validate the size of
length parameter in vms-alpha. An attacker could possibly use this issue to
cause a crash or access sensitive informati
Microsoft
A potential heap based buffer overflow was found in _bfd_elf_slurp_version_tables() in bfd/elf.c.
vendor_msrc·2023-05-09·CVSS 6.5
CVE-2023-1972 [MEDIUM] CWE-119 A potential heap based buffer overflow was found in _bfd_elf_slurp_version_tables() in bfd/elf.c.
A potential heap based buffer overflow was found in _bfd_elf_slurp_version_tables() in bfd/elf.c.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
Red Hat Inc.: Red Hat Inc.
Customer Action Required: Yes
Rem
Red Hat
binutils: Illegal memory access when accessing a zer0-lengthverdef table
vendor_redhat·2023-04-10·CVSS 6.5
CVE-2023-1972 [MEDIUM] CWE-787 binutils: Illegal memory access when accessing a zer0-lengthverdef table
binutils: Illegal memory access when accessing a zer0-lengthverdef table
A potential heap based buffer overflow was found in _bfd_elf_slurp_version_tables() in bfd/elf.c. This may lead to loss of availability.
A potential heap-based buffer overflow was found in binutils in the _bfd_elf_slurp_version_tables() function in bfd/elf.c. This issue may lead to a loss of availability.
Statement: This issue is classified with a low severity primarily because binutils is not typically exposed to untrusted inputs in most environments, limiting the possibility of exploitation. Additionally, this heap-based buffer overflow is only triggered during the parsing of a specially crafted file, requiring an attacker to convince a user to process this file with objdump. Furthermore, binutils does not handle
Debian
CVE-2023-1972: binutils - A potential heap based buffer overflow was found in _bfd_elf_slurp_version_table...
vendor_debian·2023·CVSS 6.5
CVE-2023-1972 [MEDIUM] CVE-2023-1972: binutils - A potential heap based buffer overflow was found in _bfd_elf_slurp_version_table...
A potential heap based buffer overflow was found in _bfd_elf_slurp_version_tables() in bfd/elf.c. This may lead to loss of availability.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 2.41-1)
sid: resolved (fixed in 2.41-1)
trixie: resolved (fixed in 2.41-1)
No detection rules found.
No public exploits indexed.
2023-05-17
Published