Debian Binutils vulnerabilities
259 known vulnerabilities affecting debian/binutils.
Total CVEs
259
CISA KEV
0
Public exploits
12
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH40MEDIUM23LOW193
Vulnerabilities
Page 10 of 13
CVE-2017-6965P4MEDIUMCVSS 5.5fixed in binutils 2.28-3 (bookworm)2017
CVE-2017-6965 [MEDIUM] CVE-2017-6965: binutils - readelf in GNU Binutils 2.28 writes to illegal addresses while processing corrup...
readelf in GNU Binutils 2.28 writes to illegal addresses while processing corrupt input files containing symbol-difference relocations, leading to a heap-based buffer overflow.
Scope: local
bookworm: resolved (fixed in 2.28-3)
bullseye: resolved (fixed in 2.28-3)
forky: resolved (fixed in 2.28-3)
sid: resolved (fixed in 2.28-3)
trixie: resolved (fixed in 2.28-3)
debian
CVE-2020-35493P4LOWCVSS 5.5fixed in binutils 2.33.50.20200107-1 (bookworm)2020
CVE-2020-35493 [MEDIUM] CVE-2020-35493: binutils - A flaw exists in binutils in bfd/pef.c. An attacker who is able to submit a craf...
A flaw exists in binutils in bfd/pef.c. An attacker who is able to submit a crafted PEF file to be parsed by objdump could cause a heap buffer overflow -> out-of-bounds read that could lead to an impact to application availability. This flaw affects binutils versions prior to 2.34.
Scope: local
bookworm: resolved (fixed in 2.33.50.20200107-1)
bullseye: resolved (
debian
CVE-2022-48064P4LOWCVSS 5.5fixed in binutils 2.40-2 (bookworm)2022
CVE-2022-48064 [MEDIUM] CVE-2022-48064: binutils - GNU Binutils before 2.40 was discovered to contain an excessive memory consumpti...
GNU Binutils before 2.40 was discovered to contain an excessive memory consumption vulnerability via the function bfd_dwarf2_find_nearest_line_with_alt at dwarf2.c. The attacker could supply a crafted ELF file and cause a DNS attack.
Scope: local
bookworm: resolved (fixed in 2.40-2)
bullseye: open
forky: resolved (fixed in 2.40-2)
sid: resolved (fixed in 2.40-2)
debian
CVE-2022-48063P4LOWCVSS 5.5fixed in binutils 2.40-2 (bookworm)2022
CVE-2022-48063 [MEDIUM] CVE-2022-48063: binutils - GNU Binutils before 2.40 was discovered to contain an excessive memory consumpti...
GNU Binutils before 2.40 was discovered to contain an excessive memory consumption vulnerability via the function load_separate_debug_files at dwarf2.c. The attacker could supply a crafted ELF file and cause a DNS attack.
Scope: local
bookworm: resolved (fixed in 2.40-2)
bullseye: open
forky: resolved (fixed in 2.40-2)
sid: resolved (fixed in 2.40-2)
trixie: reso
debian
CVE-2016-4492P4LOWCVSS 4.4fixed in binutils 2.27.51.20161102-1 (bookworm)2016
CVE-2016-4492 [MEDIUM] CVE-2016-4492: binutils - Buffer overflow in the do_type function in cplus-dem.c in libiberty allows remot...
Buffer overflow in the do_type function in cplus-dem.c in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary.
Scope: local
bookworm: resolved (fixed in 2.27.51.20161102-1)
bullseye: resolved (fixed in 2.27.51.20161102-1)
forky: resolved (fixed in 2.27.51.20161102-1)
sid: resolved (fixed in 2.27.51.2016
debian
CVE-2018-10535P4MEDIUMCVSS 5.5fixed in binutils 2.30.90.20180627-1 (bookworm)2018
CVE-2018-10535 [MEDIUM] CVE-2018-10535: binutils - The ignore_section_sym function in elf.c in the Binary File Descriptor (BFD) lib...
The ignore_section_sym function in elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, does not validate the output_section pointer in the case of a symtab entry with a "SECTION" type that has a "0" value, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) vi
debian
CVE-2018-6759P4MEDIUMCVSS 5.5fixed in binutils 2.30-3 (bookworm)2018
CVE-2018-6759 [MEDIUM] CVE-2018-6759: binutils - The bfd_get_debug_link_info_1 function in opncls.c in the Binary File Descriptor...
The bfd_get_debug_link_info_1 function in opncls.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, has an unchecked strnlen operation. Remote attackers could leverage this vulnerability to cause a denial of service (segmentation fault) via a crafted ELF file.
Scope: local
bookworm: resolved (fixed in 2.30-3)
bullseye:
debian
CVE-2017-9039P4LOWCVSS 5.5fixed in binutils 2.28-6 (bookworm)2017
CVE-2017-9039 [MEDIUM] CVE-2017-9039: binutils - GNU Binutils 2.28 allows remote attackers to cause a denial of service (memory c...
GNU Binutils 2.28 allows remote attackers to cause a denial of service (memory consumption) via a crafted ELF file with many program headers, related to the get_program_headers function in readelf.c.
Scope: local
bookworm: resolved (fixed in 2.28-6)
bullseye: resolved (fixed in 2.28-6)
forky: resolved (fixed in 2.28-6)
sid: resolved (fixed in 2.28-6)
trixie: resolv
debian
CVE-2018-8945P4LOWCVSS 5.5fixed in binutils 2.30.90.20180627-1 (bookworm)2018
CVE-2018-8945 [MEDIUM] CVE-2018-8945: binutils - The bfd_section_from_shdr function in elf.c in the Binary File Descriptor (BFD) ...
The bfd_section_from_shdr function in elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to cause a denial of service (segmentation fault) via a large attribute section.
Scope: local
bookworm: resolved (fixed in 2.30.90.20180627-1)
bullseye: resolved (fixed in 2.30.90.20180627-1)
forky: resol
debian
CVE-2017-15021P4LOWCVSS 5.5fixed in binutils 2.29.90.20180122-1 (bookworm)2017
CVE-2017-15021 [MEDIUM] CVE-2017-15021: binutils - bfd_get_debug_link_info_1 in opncls.c in the Binary File Descriptor (BFD) librar...
bfd_get_debug_link_info_1 in opncls.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file, related to bfd_getl32.
Scope: local
bookworm: resolved (fixed in 2.29.90.20180122-1)
bullseye: resolved
debian
CVE-2018-7642P4MEDIUMCVSS 5.5fixed in binutils 2.30-6 (bookworm)2018
CVE-2018-7642 [MEDIUM] CVE-2018-7642: binutils - The swap_std_reloc_in function in aoutx.h in the Binary File Descriptor (BFD) li...
The swap_std_reloc_in function in aoutx.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to cause a denial of service (aout_32_swap_std_reloc_out NULL pointer dereference and application crash) via a crafted ELF file, as demonstrated by objcopy.
Scope: local
bookworm: resolved (fixed in 2.30-6)
debian
CVE-2017-9044P4LOWCVSS 5.5fixed in binutils 2.29-1 (bookworm)2017
CVE-2017-9044 [MEDIUM] CVE-2017-9044: binutils - The print_symbol_for_build_attribute function in readelf.c in GNU Binutils 2017-...
The print_symbol_for_build_attribute function in readelf.c in GNU Binutils 2017-04-12 allows remote attackers to cause a denial of service (invalid read and SEGV) via a crafted ELF file.
Scope: local
bookworm: resolved (fixed in 2.29-1)
bullseye: resolved (fixed in 2.29-1)
forky: resolved (fixed in 2.29-1)
sid: resolved (fixed in 2.29-1)
trixie: resolved (fixed in
debian
CVE-2016-4493P4LOWCVSS 5.5fixed in binutils 2.27.51.20161102-1 (bookworm)2016
CVE-2016-4493 [MEDIUM] CVE-2016-4493: binutils - The demangle_template_value_parm and do_hpacc_template_literal functions in cplu...
The demangle_template_value_parm and do_hpacc_template_literal functions in cplus-dem.c in libiberty allow remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted binary.
Scope: local
bookworm: resolved (fixed in 2.27.51.20161102-1)
bullseye: resolved (fixed in 2.27.51.20161102-1)
forky: resolved (fixed in 2.27.51.20161102-1)
sid:
debian
CVE-2017-14529P4MEDIUMCVSS 5.5fixed in binutils 2.29-10 (bookworm)2017
CVE-2017-14529 [MEDIUM] CVE-2017-14529: binutils - The pe_print_idata function in peXXigen.c in the Binary File Descriptor (BFD) li...
The pe_print_idata function in peXXigen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, mishandles HintName vector entries, which allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted PE file, related to the bfd_getl16 function.
Scope: local
bookworm:
debian
CVE-2019-14444P4LOWCVSS 5.5fixed in binutils 2.32.51.20190813-1 (bookworm)2019
CVE-2019-14444 [MEDIUM] CVE-2019-14444: binutils - apply_relocations in readelf.c in GNU Binutils 2.32 contains an integer overflow...
apply_relocations in readelf.c in GNU Binutils 2.32 contains an integer overflow that allows attackers to trigger a write access violation (in byte_put_little_endian function in elfcomm.c) via an ELF file, as demonstrated by readelf.
Scope: local
bookworm: resolved (fixed in 2.32.51.20190813-1)
bullseye: resolved (fixed in 2.32.51.20190813-1)
forky: resolved (fix
debian
CVE-2017-13757P4MEDIUMCVSS 5.5fixed in binutils 2.29-10 (bookworm)2017
CVE-2017-13757 [MEDIUM] CVE-2017-13757: binutils - The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Bin...
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, does not validate the PLT section size, which allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file, related to elf_i386_get_synthetic_symtab in elf32-i386.c and elf_x86_64_get_synthetic_symtab in el
debian
CVE-2018-17360P4LOWCVSS 5.5fixed in binutils 2.32.51.20190707-1 (bookworm)2018
CVE-2018-17360 [MEDIUM] CVE-2018-17360: binutils - An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd)...
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. a heap-based buffer over-read in bfd_getl32 in libbfd.c allows an attacker to cause a denial of service through a crafted PE file. This vulnerability can be triggered by the executable objdump.
Scope: local
bookworm: resolved (fixed in 2.32.51.20
debian
CVE-2018-17985P4LOWCVSS 5.5fixed in binutils 2.32.51.20190707-1 (bookworm)2018
CVE-2018-17985 [MEDIUM] CVE-2018-17985: binutils - An issue was discovered in cp-demangle.c in GNU libiberty, as distributed in GNU...
An issue was discovered in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31. There is a stack consumption problem caused by the cplus_demangle_type function making recursive calls to itself in certain scenarios involving many 'P' characters.
Scope: local
bookworm: resolved (fixed in 2.32.51.20190707-1)
bullseye: resolved (fixed in 2.32.51.20190
debian
CVE-2017-7299P4MEDIUMCVSS 5.5fixed in binutils 2.27.51.20161220-1 (bookworm)2017
CVE-2017-7299 [MEDIUM] CVE-2017-7299: binutils - The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Bin...
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has an invalid read (of size 8) because the code to emit relocs (bfd_elf_final_link function in bfd/elflink.c) does not check the format of the input file before trying to read the ELF reloc section header. The vulnerability leads to a GNU linker (ld) program crash.
Scope: l
debian
CVE-2019-1010204P4LOWCVSS 5.5fixed in binutils 2.38.50.20220627-1 (bookworm)2019
CVE-2019-1010204 [MEDIUM] CVE-2019-1010204: binutils - GNU binutils gold gold v1.11-v1.16 (GNU binutils v2.21-v2.31.1) is affected by: ...
GNU binutils gold gold v1.11-v1.16 (GNU binutils v2.21-v2.31.1) is affected by: Improper Input Validation, Signed/Unsigned Comparison, Out-of-bounds Read. The impact is: Denial of service. The component is: gold/fileread.cc:497, elfcpp/elfcpp_file.h:644. The attack vector is: An ELF file with an invalid e_shoff header field must be opened.
Scope: local
bookwo
debian