cbcvebase.

Debian Binutils vulnerabilities

259 known vulnerabilities affecting debian/binutils.

Total CVEs
259
CISA KEV
0
Public exploits
12
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH40MEDIUM23LOW193

Vulnerabilities

Page 11 of 13
CVE-2020-16592P4LOWCVSS 5.5fixed in binutils 2.35-1 (bookworm)2020
CVE-2020-16592 [MEDIUM] CVE-2020-16592: binutils - A use after free issue exists in the Binary File Descriptor (BFD) library (aka l... A use after free issue exists in the Binary File Descriptor (BFD) library (aka libbfd) in GNU Binutils 2.34 in bfd_hash_lookup, as demonstrated in nm-new, that can cause a denial of service via a crafted file. Scope: local bookworm: resolved (fixed in 2.35-1) bullseye: resolved (fixed in 2.35-1) forky: resolved (fixed in 2.35-1) sid: resolved (fixed in 2.35-1) tr
debian
CVE-2020-16590P4LOWCVSS 5.5fixed in binutils 2.35-1 (bookworm)2020
CVE-2020-16590 [MEDIUM] CVE-2020-16590: binutils - A double free vulnerability exists in the Binary File Descriptor (BFD) (aka libb... A double free vulnerability exists in the Binary File Descriptor (BFD) (aka libbrd) in GNU Binutils 2.35 in the process_symbol_table, as demonstrated in readelf, via a crafted file. Scope: local bookworm: resolved (fixed in 2.35-1) bullseye: resolved (fixed in 2.35-1) forky: resolved (fixed in 2.35-1) sid: resolved (fixed in 2.35-1) trixie: resolved (fixed in 2.3
debian
CVE-2024-57360P4LOWCVSS 5.5fixed in binutils 2.43.50.20241221-1 (forky)2024
CVE-2024-57360 [MEDIUM] CVE-2024-57360: binutils - https://www.gnu.org/software/binutils/ nm >=2.43 is affected by: Incorrect Acces... https://www.gnu.org/software/binutils/ nm >=2.43 is affected by: Incorrect Access Control. The type of exploitation is: local. The component is: `nm --without-symbol-version` function. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 2.43.50.20241221-1) sid: resolved (fixed in 2.43.50.20241221-1) trixie: resolved (fixed in 2.43.50.20241221-1)
debian
CVE-2017-14940P4LOWCVSS 5.5fixed in binutils 2.29.90.20180122-1 (bookworm)2017
CVE-2017-14940 [MEDIUM] CVE-2017-14940: binutils - scan_unit_for_symbols in dwarf2.c in the Binary File Descriptor (BFD) library (a... scan_unit_for_symbols in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted ELF file. Scope: local bookworm: resolved (fixed in 2.29.90.20180122-1) bullseye: resolved (fixed in 2.29.90.20180122-1)
debian
CVE-2018-20002P4LOWCVSS 5.5fixed in binutils 2.32.51.20190707-1 (bookworm)2018
CVE-2018-20002 [MEDIUM] CVE-2018-20002: binutils - The _bfd_generic_read_minisymbols function in syms.c in the Binary File Descript... The _bfd_generic_read_minisymbols function in syms.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31, has a memory leak via a crafted ELF file, leading to a denial of service (memory consumption), as demonstrated by nm. Scope: local bookworm: resolved (fixed in 2.32.51.20190707-1) bullseye: resolved (fixed in 2.32.51.
debian
CVE-2017-17123P4LOWCVSS 5.5fixed in binutils 2.29.90.20180122-1 (bookworm)2017
CVE-2017-17123 [MEDIUM] CVE-2017-17123: binutils - The coff_slurp_reloc_table function in coffcode.h in the Binary File Descriptor ... The coff_slurp_reloc_table function in coffcode.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted COFF based file. Scope: local bookworm: resolved (fixed in 2.29.90.20180122-1) bullseye: resolved (fix
debian
CVE-2017-14129P4LOWCVSS 5.5fixed in binutils 2.29-10 (bookworm)2017
CVE-2017-14129 [MEDIUM] CVE-2017-14129: binutils - The read_section function in dwarf2.c in the Binary File Descriptor (BFD) librar... The read_section function in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (parse_comp_unit heap-based buffer over-read and application crash) via a crafted ELF file. Scope: local bookworm: resolved (fixed in 2.29-10) bullseye: resolved (fixed in 2.29-10
debian
CVE-2017-14130P4LOWCVSS 5.5fixed in binutils 2.29-9 (bookworm)2017
CVE-2017-14130 [MEDIUM] CVE-2017-14130: binutils - The _bfd_elf_parse_attributes function in elf-attrs.c in the Binary File Descrip... The _bfd_elf_parse_attributes function in elf-attrs.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (_bfd_elf_attr_strdup heap-based buffer over-read and application crash) via a crafted ELF file. Scope: local bookworm: resolved (fixed in 2.29-9) bullseye: resolv
debian
CVE-2017-14128P4LOWCVSS 5.5fixed in binutils 2.29-9 (bookworm)2017
CVE-2017-14128 [MEDIUM] CVE-2017-14128: binutils - The decode_line_info function in dwarf2.c in the Binary File Descriptor (BFD) li... The decode_line_info function in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (read_1_byte heap-based buffer over-read and application crash) via a crafted ELF file. Scope: local bookworm: resolved (fixed in 2.29-9) bullseye: resolved (fixed in 2.29-9)
debian
CVE-2018-7570P4MEDIUMCVSS 5.5fixed in binutils 2.30-6 (bookworm)2018
CVE-2018-7570 [MEDIUM] CVE-2018-7570: binutils - The assign_file_positions_for_non_load_sections function in elf.c in the Binary ... The assign_file_positions_for_non_load_sections function in elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an ELF file with a RELRO segment that lacks a matching LOAD segment, as demonstrated by objcopy. Sco
debian
CVE-2017-17080P4LOWCVSS 5.5fixed in binutils 2.29.90.20180122-1 (bookworm)2017
CVE-2017-17080 [MEDIUM] CVE-2017-17080: binutils - elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed i... elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, does not validate sizes of core notes, which allows remote attackers to cause a denial of service (bfd_getl32 heap-based buffer over-read and application crash) via a crafted object file, related to elfcore_grok_netbsd_procinfo, elfcore_grok_openbsd_procinfo, an
debian
CVE-2017-7210P4LOWCVSS 5.5fixed in binutils 2.28-3 (bookworm)2017
CVE-2017-7210 [MEDIUM] CVE-2017-7210: binutils - objdump in GNU Binutils 2.28 is vulnerable to multiple heap-based buffer over-re... objdump in GNU Binutils 2.28 is vulnerable to multiple heap-based buffer over-reads (of size 1 and size 8) while handling corrupt STABS enum type strings in a crafted object file, leading to program crash. Scope: local bookworm: resolved (fixed in 2.28-3) bullseye: resolved (fixed in 2.28-3) forky: resolved (fixed in 2.28-3) sid: resolved (fixed in 2.28-3) trixie:
debian
CVE-2019-9073P4LOWCVSS 5.5fixed in binutils 2.32.51.20190707-1 (bookworm)2019
CVE-2019-9073 [MEDIUM] CVE-2019-9073: binutils - An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd)... An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is an attempted excessive memory allocation in _bfd_elf_slurp_version_tables in elf.c. Scope: local bookworm: resolved (fixed in 2.32.51.20190707-1) bullseye: resolved (fixed in 2.32.51.20190707-1) forky: resolved (fixed in 2.32.51.20190707-1) s
debian
CVE-2018-7569P4MEDIUMCVSS 5.5fixed in binutils 2.30-6 (bookworm)2018
CVE-2018-7569 [MEDIUM] CVE-2018-7569: binutils - dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distribute... dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to cause a denial of service (integer underflow or overflow, and application crash) via an ELF file with a corrupt DWARF FORM block, as demonstrated by nm. Scope: local bookworm: resolved (fixed in 2.30-6) bullseye: resolved (fixed in 2.30
debian
CVE-2017-14938P4LOWCVSS 5.5fixed in binutils 2.29.90.20180122-1 (bookworm)2017
CVE-2017-14938 [MEDIUM] CVE-2017-14938: binutils - _bfd_elf_slurp_version_tables in elf.c in the Binary File Descriptor (BFD) libra... _bfd_elf_slurp_version_tables in elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted ELF file. Scope: local bookworm: resolved (fixed in 2.29.90.20180122-1) bullseye: resolved (fixed in 2.29.90.201
debian
CVE-2018-7568P4MEDIUMCVSS 5.5fixed in binutils 2.30-6 (bookworm)2018
CVE-2018-7568 [MEDIUM] CVE-2018-7568: binutils - The parse_die function in dwarf1.c in the Binary File Descriptor (BFD) library (... The parse_die function in dwarf1.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to cause a denial of service (integer overflow and application crash) via an ELF file with corrupt dwarf1 debug information, as demonstrated by nm. Scope: local bookworm: resolved (fixed in 2.30-6) bullseye: resol
debian
CVE-2017-14930P4LOWCVSS 5.5fixed in binutils 2.29.90.20180122-1 (bookworm)2017
CVE-2017-14930 [MEDIUM] CVE-2017-14930: binutils - Memory leak in decode_line_info in dwarf2.c in the Binary File Descriptor (BFD) ... Memory leak in decode_line_info in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (memory consumption) via a crafted ELF file. Scope: local bookworm: resolved (fixed in 2.29.90.20180122-1) bullseye: resolved (fixed in 2.29.90.20180122-1) forky: resolved (
debian
CVE-2017-15225P4LOWCVSS 5.5fixed in binutils 2.29.90.20180122-1 (bookworm)2017
CVE-2017-15225 [MEDIUM] CVE-2017-15225: binutils - _bfd_dwarf2_cleanup_debug_info in dwarf2.c in the Binary File Descriptor (BFD) l... _bfd_dwarf2_cleanup_debug_info in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (memory leak) via a crafted ELF file. Scope: local bookworm: resolved (fixed in 2.29.90.20180122-1) bullseye: resolved (fixed in 2.29.90.20180122-1) forky: resolved (fixed in
debian
CVE-2017-7224P4MEDIUMCVSS 5.5fixed in binutils 2.27.51.20161201-1 (bookworm)2017
CVE-2017-7224 [MEDIUM] CVE-2017-7224: binutils - The find_nearest_line function in objdump in GNU Binutils 2.28 is vulnerable to ... The find_nearest_line function in objdump in GNU Binutils 2.28 is vulnerable to an invalid write (of size 1) while disassembling a corrupt binary that contains an empty function name, leading to a program crash. Scope: local bookworm: resolved (fixed in 2.27.51.20161201-1) bullseye: resolved (fixed in 2.27.51.20161201-1) forky: resolved (fixed in 2.27.51.20161201-1
debian
CVE-2018-9138P4LOWCVSS 5.5fixed in binutils 2.32.51.20190707-1 (bookworm)2018
CVE-2018-9138 [MEDIUM] CVE-2018-9138: binutils - An issue was discovered in cplus-dem.c in GNU libiberty, as distributed in GNU B... An issue was discovered in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.29 and 2.30. Stack Exhaustion occurs in the C++ demangling functions provided by libiberty, and there are recursive stack frames: demangle_nested_args, demangle_args, do_arg, and do_type. Scope: local bookworm: resolved (fixed in 2.32.51.20190707-1) bullseye: resolved (fixed i
debian
Debian Binutils vulnerabilities | cvebase