cbcvebase.

Debian Binutils vulnerabilities

259 known vulnerabilities affecting debian/binutils.

Total CVEs
259
CISA KEV
0
Public exploits
12
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH40MEDIUM23LOW193

Vulnerabilities

Page 12 of 13
CVE-2017-9955P4MEDIUMCVSS 5.5fixed in binutils 2.29-1 (bookworm)2017
CVE-2017-9955 [MEDIUM] CVE-2017-9955: binutils - The get_build_id function in opncls.c in the Binary File Descriptor (BFD) librar... The get_build_id function in opncls.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file in which a certain size field is larger than a corresponding data field, as demonstrated by mishandling within
debian
CVE-2017-14974P4MEDIUMCVSS 5.5fixed in binutils 2.29.1-2 (bookworm)2017
CVE-2017-14974 [MEDIUM] CVE-2017-14974: binutils - The *_get_synthetic_symtab functions in the Binary File Descriptor (BFD) library... The *_get_synthetic_symtab functions in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, mishandle the failure of a certain canonicalization step, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted ELF file, related to elf32-i386.c and elf64-x86-64.c.
debian
CVE-2017-8421P4MEDIUMCVSS 5.5fixed in binutils 2.28-5 (bookworm)2017
CVE-2017-8421 [MEDIUM] CVE-2017-8421: binutils - The function coff_set_alignment_hook in coffcode.h in Binary File Descriptor (BF... The function coff_set_alignment_hook in coffcode.h in Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has a memory leak vulnerability which can cause memory exhaustion in objdump via a crafted PE file. Additional validation in dump_relocs_in_section in objdump.c can resolve this. Scope: local bookworm: resolved (fixed in 2.28
debian
CVE-2021-46195P4LOWCVSS 5.5fixed in binutils 2.37.90.20220207-1 (bookworm)2021
CVE-2021-46195 [MEDIUM] CVE-2021-46195: binutils - GCC v12.0 was discovered to contain an uncontrolled recursion via the component ... GCC v12.0 was discovered to contain an uncontrolled recursion via the component libiberty/rust-demangle.c. This vulnerability allows attackers to cause a Denial of Service (DoS) by consuming excessive CPU and memory resources. Scope: local bookworm: resolved (fixed in 2.37.90.20220207-1) bullseye: open forky: resolved (fixed in 2.37.90.20220207-1) sid: resolved (
debian
CVE-2022-48065P4LOWCVSS 5.5fixed in binutils 2.40-2 (bookworm)2022
CVE-2022-48065 [MEDIUM] CVE-2022-48065: binutils - GNU Binutils before 2.40 was discovered to contain a memory leak vulnerability v... GNU Binutils before 2.40 was discovered to contain a memory leak vulnerability var the function find_abstract_instance in dwarf2.c. Scope: local bookworm: resolved (fixed in 2.40-2) bullseye: open forky: resolved (fixed in 2.40-2) sid: resolved (fixed in 2.40-2) trixie: resolved (fixed in 2.40-2)
debian
CVE-2022-4285P4LOWCVSS 5.5fixed in binutils 2.39.50.20221208-2 (bookworm)2022
CVE-2022-4285 [MEDIUM] CVE-2022-4285: binutils - An illegal memory access flaw was found in the binutils package. Parsing an ELF ... An illegal memory access flaw was found in the binutils package. Parsing an ELF file containing corrupt symbol version information may result in a denial of service. This issue is the result of an incomplete fix for CVE-2020-16599. Scope: local bookworm: resolved (fixed in 2.39.50.20221208-2) bullseye: open forky: resolved (fixed in 2.39.50.20221208-2) sid: resolve
debian
CVE-2022-38533P4LOWCVSS 5.5fixed in binutils 2.39.50.20221208-2 (bookworm)2022
CVE-2022-38533 [MEDIUM] CVE-2022-38533: binutils - In GNU Binutils before 2.40, there is a heap-buffer-overflow in the error functi... In GNU Binutils before 2.40, there is a heap-buffer-overflow in the error function bfd_getl32 when called from the strip_main function in strip-new via a crafted file. Scope: local bookworm: resolved (fixed in 2.39.50.20221208-2) bullseye: open forky: resolved (fixed in 2.39.50.20221208-2) sid: resolved (fixed in 2.39.50.20221208-2) trixie: resolved (fixed in 2.3
debian
CVE-2022-35206P4LOWCVSS 5.5fixed in binutils 2.38.50.20220627-1 (bookworm)2022
CVE-2022-35206 [MEDIUM] CVE-2022-35206: binutils - Null pointer dereference vulnerability in Binutils readelf 2.38.50 via function ... Null pointer dereference vulnerability in Binutils readelf 2.38.50 via function read_and_display_attr_value in file dwarf.c. Scope: local bookworm: resolved (fixed in 2.38.50.20220627-1) bullseye: open forky: resolved (fixed in 2.38.50.20220627-1) sid: resolved (fixed in 2.38.50.20220627-1) trixie: resolved (fixed in 2.38.50.20220627-1)
debian
CVE-2014-8737P4LOWCVSS 3.6fixed in binutils 2.24.90.20141124-1 (bookworm)2014
CVE-2014-8737 [LOW] CVE-2014-8737: binutils - Multiple directory traversal vulnerabilities in GNU binutils 2.24 and earlier al... Multiple directory traversal vulnerabilities in GNU binutils 2.24 and earlier allow local users to delete arbitrary files via a .. (dot dot) or full path name in an archive to (1) strip or (2) objcopy or create arbitrary files via (3) a .. (dot dot) or full path name in an archive to ar. Scope: local bookworm: resolved (fixed in 2.24.90.20141124-1) bullseye: resolved
debian
CVE-2017-15025P4LOWCVSS 5.5fixed in binutils 2.29.90.20180122-1 (bookworm)2017
CVE-2017-15025 [MEDIUM] CVE-2017-15025: binutils - decode_line_info in dwarf2.c in the Binary File Descriptor (BFD) library (aka li... decode_line_info in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted ELF file. Scope: local bookworm: resolved (fixed in 2.29.90.20180122-1) bullseye: resolved (fixed in 2.29.90.20180122-1) forky: r
debian
CVE-2017-15024P4LOWCVSS 5.5fixed in binutils 2.29.90.20180122-1 (bookworm)2017
CVE-2017-15024 [MEDIUM] CVE-2017-15024: binutils - find_abstract_instance_name in dwarf2.c in the Binary File Descriptor (BFD) libr... find_abstract_instance_name in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (infinite recursion and application crash) via a crafted ELF file. Scope: local bookworm: resolved (fixed in 2.29.90.20180122-1) bullseye: resolved (fixed in 2.29.90.20180122-1)
debian
CVE-2018-17358P4LOWCVSS 5.5fixed in binutils 2.32.51.20190707-1 (bookworm)2018
CVE-2018-17358 [MEDIUM] CVE-2018-17358: binutils - An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd)... An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. An invalid memory access exists in _bfd_stab_section_find_nearest_line in syms.c. Attackers could leverage this vulnerability to cause a denial of service (application crash) via a crafted ELF file. Scope: local bookworm: resolved (fixed in 2.32.
debian
CVE-2017-14932P4LOWCVSS 5.5fixed in binutils 2.29.90.20180122-1 (bookworm)2017
CVE-2017-14932 [MEDIUM] CVE-2017-14932: binutils - decode_line_info in dwarf2.c in the Binary File Descriptor (BFD) library (aka li... decode_line_info in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (infinite loop) via a crafted ELF file. Scope: local bookworm: resolved (fixed in 2.29.90.20180122-1) bullseye: resolved (fixed in 2.29.90.20180122-1) forky: resolved (fixed in 2.29.90.201
debian
CVE-2018-17359P4LOWCVSS 5.5fixed in binutils 2.32.51.20190707-1 (bookworm)2018
CVE-2018-17359 [MEDIUM] CVE-2018-17359: binutils - An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd)... An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. An invalid memory access exists in bfd_zalloc in opncls.c. Attackers could leverage this vulnerability to cause a denial of service (application crash) via a crafted ELF file. Scope: local bookworm: resolved (fixed in 2.32.51.20190707-1) bullseye
debian
CVE-2017-14933P4LOWCVSS 5.5fixed in binutils 2.29.90.20180122-1 (bookworm)2017
CVE-2017-14933 [MEDIUM] CVE-2017-14933: binutils - read_formatted_entries in dwarf2.c in the Binary File Descriptor (BFD) library (... read_formatted_entries in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (infinite loop) via a crafted ELF file. Scope: local bookworm: resolved (fixed in 2.29.90.20180122-1) bullseye: resolved (fixed in 2.29.90.20180122-1) forky: resolved (fixed in 2.29.
debian
CVE-2017-7209P4LOWCVSS 5.5fixed in binutils 2.28-3 (bookworm)2017
CVE-2017-7209 [MEDIUM] CVE-2017-7209: binutils - The dump_section_as_bytes function in readelf in GNU Binutils 2.28 accesses a NU... The dump_section_as_bytes function in readelf in GNU Binutils 2.28 accesses a NULL pointer while reading section contents in a corrupt binary, leading to a program crash. Scope: local bookworm: resolved (fixed in 2.28-3) bullseye: resolved (fixed in 2.28-3) forky: resolved (fixed in 2.28-3) sid: resolved (fixed in 2.28-3) trixie: resolved (fixed in 2.28-3)
debian
CVE-2020-16593P4LOWCVSS 5.5fixed in binutils 2.35-1 (bookworm)2020
CVE-2020-16593 [MEDIUM] CVE-2020-16593: binutils - A Null Pointer Dereference vulnerability exists in the Binary File Descriptor (B... A Null Pointer Dereference vulnerability exists in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.35, in scan_unit_for_symbols, as demonstrated in addr2line, that can cause a denial of service via a crafted file. Scope: local bookworm: resolved (fixed in 2.35-1) bullseye: resolved (fixed in 2.35-1) forky: resolved (fixed i
debian
CVE-2020-16599P4LOWCVSS 5.5fixed in binutils 2.35-1 (bookworm)2020
CVE-2020-16599 [MEDIUM] CVE-2020-16599: binutils - A Null Pointer Dereference vulnerability exists in the Binary File Descriptor (B... A Null Pointer Dereference vulnerability exists in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.35, in _bfd_elf_get_symbol_version_string, as demonstrated in nm-new, that can cause a denial of service via a crafted file. Scope: local bookworm: resolved (fixed in 2.35-1) bullseye: resolved (fixed in 2.35-1) forky: resolve
debian
CVE-2017-6966P4MEDIUMCVSS 5.5fixed in binutils 2.28-3 (bookworm)2017
CVE-2017-6966 [MEDIUM] CVE-2017-6966: binutils - readelf in GNU Binutils 2.28 has a use-after-free (specifically read-after-free)... readelf in GNU Binutils 2.28 has a use-after-free (specifically read-after-free) error while processing multiple, relocated sections in an MSP430 binary. This is caused by mishandling of an invalid symbol index, and mishandling of state across invocations. Scope: local bookworm: resolved (fixed in 2.28-3) bullseye: resolved (fixed in 2.28-3) forky: resolved (fixed
debian
CVE-2020-16591P4LOWCVSS 5.5fixed in binutils 2.35-1 (bookworm)2020
CVE-2020-16591 [MEDIUM] CVE-2020-16591: binutils - A Denial of Service vulnerability exists in the Binary File Descriptor (BFD) in ... A Denial of Service vulnerability exists in the Binary File Descriptor (BFD) in GNU Binutils 2.35 due to an invalid read in process_symbol_table, as demonstrated in readeif. Scope: local bookworm: resolved (fixed in 2.35-1) bullseye: resolved (fixed in 2.35-1) forky: resolved (fixed in 2.35-1) sid: resolved (fixed in 2.35-1) trixie: resolved (fixed in 2.35-1)
debian