cbcvebase.

Debian Binutils vulnerabilities

259 known vulnerabilities affecting debian/binutils.

Total CVEs
259
CISA KEV
0
Public exploits
12
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH40MEDIUM23LOW193

Vulnerabilities

Page 13 of 13
CVE-2020-19724P4LOWCVSS 5.5fixed in binutils 2.33.50.20200114-1 (bookworm)2020
CVE-2020-19724 [MEDIUM] CVE-2020-19724: binutils - A memory consumption issue in get_data function in binutils/nm.c in GNU nm befor... A memory consumption issue in get_data function in binutils/nm.c in GNU nm before 2.34 allows attackers to cause a denial of service via crafted command. Scope: local bookworm: resolved (fixed in 2.33.50.20200114-1) bullseye: resolved (fixed in 2.33.50.20200114-1) forky: resolved (fixed in 2.33.50.20200114-1) sid: resolved (fixed in 2.33.50.20200114-1) trixie: re
debian
CVE-2023-25585P4LOWCVSS 4.7fixed in binutils 2.39.50.20221224-1 (bookworm)2023
CVE-2023-25585 [MEDIUM] CVE-2023-25585: binutils - A flaw was found in Binutils. The use of an uninitialized field in the struct mo... A flaw was found in Binutils. The use of an uninitialized field in the struct module *module may lead to application crash and local denial of service. Scope: local bookworm: resolved (fixed in 2.39.50.20221224-1) bullseye: open forky: resolved (fixed in 2.39.50.20221224-1) sid: resolved (fixed in 2.39.50.20221224-1) trixie: resolved (fixed in 2.39.50.20221224-1)
debian
CVE-2023-25586P4LOWCVSS 4.7fixed in binutils 2.39.50.20221208-1 (bookworm)2023
CVE-2023-25586 [MEDIUM] CVE-2023-25586: binutils - A flaw was found in Binutils. A logic fail in the bfd_init_section_decompress_st... A flaw was found in Binutils. A logic fail in the bfd_init_section_decompress_status function may lead to the use of an uninitialized variable that can cause a crash and local denial of service. Scope: local bookworm: resolved (fixed in 2.39.50.20221208-1) bullseye: open forky: resolved (fixed in 2.39.50.20221208-1) sid: resolved (fixed in 2.39.50.20221208-1) tri
debian
CVE-2017-14934P4LOWCVSS 5.5fixed in binutils 2.29.90.20180122-1 (bookworm)2017
CVE-2017-14934 [MEDIUM] CVE-2017-14934: binutils - process_debug_info in dwarf.c in the Binary File Descriptor (BFD) library (aka l... process_debug_info in dwarf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (infinite loop) via a crafted ELF file that contains a negative size value in a CU structure. Scope: local bookworm: resolved (fixed in 2.29.90.20180122-1) bullseye: resolved (fixed in 2.
debian
CVE-2022-47010P4LOWCVSS 5.5fixed in binutils 2.38.50.20220627-1 (bookworm)2022
CVE-2022-47010 [MEDIUM] CVE-2022-47010: binutils - An issue was discovered function pr_function_type in prdbg.c in Binutils 2.34 th... An issue was discovered function pr_function_type in prdbg.c in Binutils 2.34 thru 2.38, allows attackers to cause a denial of service due to memory leaks. Scope: local bookworm: resolved (fixed in 2.38.50.20220627-1) bullseye: open forky: resolved (fixed in 2.38.50.20220627-1) sid: resolved (fixed in 2.38.50.20220627-1) trixie: resolved (fixed in 2.38.50.2022062
debian
CVE-2022-47007P4LOWCVSS 5.5fixed in binutils 2.38.50.20220627-1 (bookworm)2022
CVE-2022-47007 [MEDIUM] CVE-2022-47007: binutils - An issue was discovered function stab_demangle_v3_arg in stabs.c in Binutils 2.3... An issue was discovered function stab_demangle_v3_arg in stabs.c in Binutils 2.34 thru 2.38, allows attackers to cause a denial of service due to memory leaks. Scope: local bookworm: resolved (fixed in 2.38.50.20220627-1) bullseye: open forky: resolved (fixed in 2.38.50.20220627-1) sid: resolved (fixed in 2.38.50.20220627-1) trixie: resolved (fixed in 2.38.50.202
debian
CVE-2022-47011P4LOWCVSS 5.5fixed in binutils 2.38.50.20220627-1 (bookworm)2022
CVE-2022-47011 [MEDIUM] CVE-2022-47011: binutils - An issue was discovered function parse_stab_struct_fields in stabs.c in Binutils... An issue was discovered function parse_stab_struct_fields in stabs.c in Binutils 2.34 thru 2.38, allows attackers to cause a denial of service due to memory leaks. Scope: local bookworm: resolved (fixed in 2.38.50.20220627-1) bullseye: open forky: resolved (fixed in 2.38.50.20220627-1) sid: resolved (fixed in 2.38.50.20220627-1) trixie: resolved (fixed in 2.38.50
debian
CVE-2022-47008P4LOWCVSS 5.5fixed in binutils 2.38.50.20220627-1 (bookworm)2022
CVE-2022-47008 [MEDIUM] CVE-2022-47008: binutils - An issue was discovered function make_tempdir, and make_tempname in bucomm.c in ... An issue was discovered function make_tempdir, and make_tempname in bucomm.c in Binutils 2.34 thru 2.38, allows attackers to cause a denial of service due to memory leaks. Scope: local bookworm: resolved (fixed in 2.38.50.20220627-1) bullseye: open forky: resolved (fixed in 2.38.50.20220627-1) sid: resolved (fixed in 2.38.50.20220627-1) trixie: resolved (fixed in
debian
CVE-2020-21490P4LOWCVSS 5.5fixed in binutils 2.33.50.20200107-1 (bookworm)2020
CVE-2020-21490 [MEDIUM] CVE-2020-21490: binutils - An issue was discovered in GNU Binutils 2.34. It is a memory leak when process m... An issue was discovered in GNU Binutils 2.34. It is a memory leak when process microblaze-dis.c. This one will consume memory on each insn disassembled. Scope: local bookworm: resolved (fixed in 2.33.50.20200107-1) bullseye: resolved (fixed in 2.33.50.20200107-1) forky: resolved (fixed in 2.33.50.20200107-1) sid: resolved (fixed in 2.33.50.20200107-1) trixie: res
debian
CVE-2022-35205P4LOWCVSS 5.5fixed in binutils 2.38.50.20220627-1 (bookworm)2022
CVE-2022-35205 [MEDIUM] CVE-2022-35205: binutils - An issue was discovered in Binutils readelf 2.38.50, reachable assertion failure... An issue was discovered in Binutils readelf 2.38.50, reachable assertion failure in function display_debug_names allows attackers to cause a denial of service. Scope: local bookworm: resolved (fixed in 2.38.50.20220627-1) bullseye: open forky: resolved (fixed in 2.38.50.20220627-1) sid: resolved (fixed in 2.38.50.20220627-1) trixie: resolved (fixed in 2.38.50.202
debian
CVE-2025-1152P4LOWCVSS 2.3fixed in binutils 2.45-3 (forky)2025
CVE-2025-1152 [LOW] CVE-2025-1152: binutils - A vulnerability classified as problematic has been found in GNU Binutils 2.43. A... A vulnerability classified as problematic has been found in GNU Binutils 2.43. Affected is the function xstrdup of the file xstrdup.c of the component ld. The manipulation leads to memory leak. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the publ
debian
CVE-2023-25588P4LOWCVSS 4.7fixed in binutils 2.39.50.20221208-1 (bookworm)2023
CVE-2023-25588 [MEDIUM] CVE-2023-25588: binutils - A flaw was found in Binutils. The field `the_bfd` of `asymbol`struct is uninitia... A flaw was found in Binutils. The field `the_bfd` of `asymbol`struct is uninitialized in the `bfd_mach_o_get_synthetic_symtab` function, which may lead to an application crash and local denial of service. Scope: local bookworm: resolved (fixed in 2.39.50.20221208-1) bullseye: open forky: resolved (fixed in 2.39.50.20221208-1) sid: resolved (fixed in 2.39.50.20221
debian
CVE-2020-35448P4LOWCVSS 3.3fixed in binutils 2.37-3 (bookworm)2020
CVE-2020-35448 [LOW] CVE-2020-35448: binutils - An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd)... An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.35.1. A heap-based buffer over-read can occur in bfd_getl_signed_32 in libbfd.c because sh_entsize is not validated in _bfd_elf_slurp_secondary_reloc_section in elf.c. Scope: local bookworm: resolved (fixed in 2.37-3) bullseye: open forky: resolved (fix
debian
CVE-2025-1180P4LOWCVSS 2.3fixed in binutils 2.45-3 (forky)2025
CVE-2025-1180 [LOW] CVE-2025-1180: binutils - A vulnerability classified as problematic has been found in GNU Binutils 2.43. T... A vulnerability classified as problematic has been found in GNU Binutils 2.43. This affects the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component ld. The manipulation leads to memory corruption. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult.
debian
CVE-2025-1150P4LOWCVSS 2.3fixed in binutils 2.45-3 (forky)2025
CVE-2025-1150 [LOW] CVE-2025-1150: binutils - A vulnerability was found in GNU Binutils 2.43. It has been declared as problema... A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. This vulnerability affects the function bfd_malloc of the file libbfd.c of the component ld. The manipulation leads to memory leak. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclose
debian
CVE-2025-1148P4LOWCVSS 2.3fixed in binutils 2.45-3 (forky)2025
CVE-2025-1148 [LOW] CVE-2025-1148: binutils - A vulnerability was found in GNU Binutils 2.43 and classified as problematic. Af... A vulnerability was found in GNU Binutils 2.43 and classified as problematic. Affected by this issue is the function link_order_scan of the file ld/ldelfgen.c of the component ld. The manipulation leads to memory leak. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclo
debian
CVE-2025-1149P4LOWCVSS 2.3fixed in binutils 2.45-3 (forky)2025
CVE-2025-1149 [LOW] CVE-2025-1149: binutils - A vulnerability was found in GNU Binutils 2.43. It has been classified as proble... A vulnerability was found in GNU Binutils 2.43. It has been classified as problematic. This affects the function xstrdup of the file libiberty/xmalloc.c of the component ld. The manipulation leads to memory leak. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been
debian
CVE-2025-8225P4LOWCVSS 4.8fixed in binutils 2.45-3 (forky)2025
CVE-2025-8225 [MEDIUM] CVE-2025-8225: binutils - A vulnerability was found in GNU Binutils 2.44 and classified as problematic. Th... A vulnerability was found in GNU Binutils 2.44 and classified as problematic. This issue affects the function process_debug_info of the file binutils/dwarf.c of the component DWARF Section Handler. The manipulation leads to memory leak. Attacking locally is a requirement. The identifier of the patch is e51fdff7d2e538c0e5accdd65649ac68e6e0ddd4. It is recommended to
debian
CVE-2025-1151P4LOWCVSS 2.3fixed in binutils 2.45-3 (forky)2025
CVE-2025-1151 [LOW] CVE-2025-1151: binutils - A vulnerability was found in GNU Binutils 2.43. It has been rated as problematic... A vulnerability was found in GNU Binutils 2.43. It has been rated as problematic. This issue affects the function xmemdup of the file xmemdup.c of the component ld. The manipulation leads to memory leak. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the pub
debian
Debian Binutils vulnerabilities | cvebase