Debian Binutils vulnerabilities
285 known vulnerabilities affecting debian/binutils.
Total CVEs
285
CISA KEV
0
Public exploits
12
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH40MEDIUM23LOW219
Vulnerabilities
Page 14 of 15
CVE-2017-9044LOWCVSS 5.5fixed in binutils 2.29-1 (bookworm)2017
CVE-2017-9044 [MEDIUM] CVE-2017-9044: binutils - The print_symbol_for_build_attribute function in readelf.c in GNU Binutils 2017-...
The print_symbol_for_build_attribute function in readelf.c in GNU Binutils 2017-04-12 allows remote attackers to cause a denial of service (invalid read and SEGV) via a crafted ELF file.
Scope: local
bookworm: resolved (fixed in 2.29-1)
bullseye: resolved (fixed in 2.29-1)
forky: resolved (fixed in 2.29-1)
sid: resolved (fixed in 2.29-1)
trixie: resolved (fixed in
debian
CVE-2016-2226LOWCVSS 7.8PoCfixed in binutils 2.27.51.20161102-1 (bookworm)2016
CVE-2016-2226 [HIGH] CVE-2016-2226: binutils - Integer overflow in the string_appends function in cplus-dem.c in libiberty allo...
Integer overflow in the string_appends function in cplus-dem.c in libiberty allows remote attackers to execute arbitrary code via a crafted executable, which triggers a buffer overflow.
Scope: local
bookworm: resolved (fixed in 2.27.51.20161102-1)
bullseye: resolved (fixed in 2.27.51.20161102-1)
forky: resolved (fixed in 2.27.51.20161102-1)
sid: resolved (fixed in 2.
debian
CVE-2016-6131LOWCVSS 7.5fixed in binutils 2.27.51.20161102-1 (bookworm)2016
CVE-2016-6131 [HIGH] CVE-2016-6131: binutils - The demangler in GNU Libiberty allows remote attackers to cause a denial of serv...
The demangler in GNU Libiberty allows remote attackers to cause a denial of service (infinite loop, stack overflow, and crash) via a cycle in the references of remembered mangled types.
Scope: local
bookworm: resolved (fixed in 2.27.51.20161102-1)
bullseye: resolved (fixed in 2.27.51.20161102-1)
forky: resolved (fixed in 2.27.51.20161102-1)
sid: resolved (fixed in 2.
debian
CVE-2016-4493LOWCVSS 5.5fixed in binutils 2.27.51.20161102-1 (bookworm)2016
CVE-2016-4493 [MEDIUM] CVE-2016-4493: binutils - The demangle_template_value_parm and do_hpacc_template_literal functions in cplu...
The demangle_template_value_parm and do_hpacc_template_literal functions in cplus-dem.c in libiberty allow remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted binary.
Scope: local
bookworm: resolved (fixed in 2.27.51.20161102-1)
bullseye: resolved (fixed in 2.27.51.20161102-1)
forky: resolved (fixed in 2.27.51.20161102-1)
sid:
debian
CVE-2016-4490LOWCVSS 5.5fixed in binutils 2.27.51.20161102-1 (bookworm)2016
CVE-2016-4490 [MEDIUM] CVE-2016-4490: binutils - Integer overflow in cp-demangle.c in libiberty allows remote attackers to cause ...
Integer overflow in cp-demangle.c in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary, related to inconsistent use of the long and int types for lengths.
Scope: local
bookworm: resolved (fixed in 2.27.51.20161102-1)
bullseye: resolved (fixed in 2.27.51.20161102-1)
forky: resolved (fixed in 2.27.51.20
debian
CVE-2016-4492LOWCVSS 4.4fixed in binutils 2.27.51.20161102-1 (bookworm)2016
CVE-2016-4492 [MEDIUM] CVE-2016-4492: binutils - Buffer overflow in the do_type function in cplus-dem.c in libiberty allows remot...
Buffer overflow in the do_type function in cplus-dem.c in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary.
Scope: local
bookworm: resolved (fixed in 2.27.51.20161102-1)
bullseye: resolved (fixed in 2.27.51.20161102-1)
forky: resolved (fixed in 2.27.51.20161102-1)
sid: resolved (fixed in 2.27.51.2016
debian
CVE-2016-4489LOWCVSS 5.5fixed in binutils 2.27.51.20161102-1 (bookworm)2016
CVE-2016-4489 [MEDIUM] CVE-2016-4489: binutils - Integer overflow in the gnu_special function in libiberty allows remote attacker...
Integer overflow in the gnu_special function in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary, related to the "demangling of virtual tables."
Scope: local
bookworm: resolved (fixed in 2.27.51.20161102-1)
bullseye: resolved (fixed in 2.27.51.20161102-1)
forky: resolved (fixed in 2.27.51.20161102-1)
debian
CVE-2016-4487LOWCVSS 5.5fixed in binutils 2.27.51.20161102-1 (bookworm)2016
CVE-2016-4487 [MEDIUM] CVE-2016-4487: binutils - Use-after-free vulnerability in libiberty allows remote attackers to cause a den...
Use-after-free vulnerability in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary, related to "btypevec."
Scope: local
bookworm: resolved (fixed in 2.27.51.20161102-1)
bullseye: resolved (fixed in 2.27.51.20161102-1)
forky: resolved (fixed in 2.27.51.20161102-1)
sid: resolved (fixed in 2.27.51.2016110
debian
CVE-2016-4491LOWCVSS 5.5fixed in binutils 2.28-3 (bookworm)2016
CVE-2016-4491 [MEDIUM] CVE-2016-4491: binutils - The d_print_comp function in cp-demangle.c in libiberty allows remote attackers ...
The d_print_comp function in cp-demangle.c in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary, which triggers infinite recursion and a buffer overflow, related to a node having "itself as ancestor more than once."
Scope: local
bookworm: resolved (fixed in 2.28-3)
bullseye: resolved (fixed in 2.28-3)
debian
CVE-2016-4488LOWCVSS 5.5fixed in binutils 2.27.51.20161102-1 (bookworm)2016
CVE-2016-4488 [MEDIUM] CVE-2016-4488: binutils - Use-after-free vulnerability in libiberty allows remote attackers to cause a den...
Use-after-free vulnerability in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary, related to "ktypevec."
Scope: local
bookworm: resolved (fixed in 2.27.51.20161102-1)
bullseye: resolved (fixed in 2.27.51.20161102-1)
forky: resolved (fixed in 2.27.51.20161102-1)
sid: resolved (fixed in 2.27.51.2016110
debian
CVE-2014-9939CRITICALCVSS 9.8fixed in binutils 2.25.90.20151125-1 (bookworm)2014
CVE-2014-9939 [CRITICAL] CVE-2014-9939: binutils - ihex.c in GNU Binutils before 2.26 contains a stack buffer overflow when printin...
ihex.c in GNU Binutils before 2.26 contains a stack buffer overflow when printing bad bytes in Intel Hex objects.
Scope: local
bookworm: resolved (fixed in 2.25.90.20151125-1)
bullseye: resolved (fixed in 2.25.90.20151125-1)
forky: resolved (fixed in 2.25.90.20151125-1)
sid: resolved (fixed in 2.25.90.20151125-1)
trixie: resolved (fixed in 2.25.90.20151125-1)
debian
CVE-2014-8504HIGHCVSS 7.5fixed in binutils 2.24.90.20141104-1 (bookworm)2014
CVE-2014-8504 [HIGH] CVE-2014-8504: binutils - Stack-based buffer overflow in the srec_scan function in bfd/srec.c in GNU binut...
Stack-based buffer overflow in the srec_scan function in bfd/srec.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly have other unspecified impact via a crafted file.
Scope: local
bookworm: resolved (fixed in 2.24.90.20141104-1)
bullseye: resolved (fixed in 2.24.90.20141104-1)
forky: resolved (fixed in 2.24.90
debian
CVE-2014-8485HIGHCVSS 7.5fixed in binutils 2.24.90.20141104-1 (bookworm)2014
CVE-2014-8485 [HIGH] CVE-2014-8485: binutils - The setup_group function in bfd/elf.c in libbfd in GNU binutils 2.24 and earlier...
The setup_group function in bfd/elf.c in libbfd in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted section group headers in an ELF file.
Scope: local
bookworm: resolved (fixed in 2.24.90.20141104-1)
bullseye: resolved (fixed in 2.24.90.20141104-1)
forky: resolved (fixed in 2.24
debian
CVE-2014-8501HIGHCVSS 7.5fixed in binutils 2.24.90.20141104-1 (bookworm)2014
CVE-2014-8501 [HIGH] CVE-2014-8501: binutils - The _bfd_XXi_swap_aouthdr_in function in bfd/peXXigen.c in GNU binutils 2.24 and...
The _bfd_XXi_swap_aouthdr_in function in bfd/peXXigen.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (out-of-bounds write) and possibly have other unspecified impact via a crafted NumberOfRvaAndSizes field in the AOUT header in a PE executable.
Scope: local
bookworm: resolved (fixed in 2.24.90.20141104-1)
bullseye: resolved (f
debian
CVE-2014-8502HIGHCVSS 7.5fixed in binutils 2.24.90.20141104-1 (bookworm)2014
CVE-2014-8502 [HIGH] CVE-2014-8502: binutils - Heap-based buffer overflow in the pe_print_edata function in bfd/peXXigen.c in G...
Heap-based buffer overflow in the pe_print_edata function in bfd/peXXigen.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly have other unspecified impact via a truncated export table in a PE file.
Scope: local
bookworm: resolved (fixed in 2.24.90.20141104-1)
bullseye: resolved (fixed in 2.24.90.20141104-1)
fo
debian
CVE-2014-8503HIGHCVSS 7.5fixed in binutils 2.24.90.20141104-1 (bookworm)2014
CVE-2014-8503 [HIGH] CVE-2014-8503: binutils - Stack-based buffer overflow in the ihex_scan function in bfd/ihex.c in GNU binut...
Stack-based buffer overflow in the ihex_scan function in bfd/ihex.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly have other unspecified impact via a crafted ihex file.
Scope: local
bookworm: resolved (fixed in 2.24.90.20141104-1)
bullseye: resolved (fixed in 2.24.90.20141104-1)
forky: resolved (fixed in 2.
debian
CVE-2014-8484MEDIUMCVSS 5.0fixed in binutils 2.24.51.20140903-1 (bookworm)2014
CVE-2014-8484 [MEDIUM] CVE-2014-8484: binutils - The srec_scan function in bfd/srec.c in libdbfd in GNU binutils before 2.25 allo...
The srec_scan function in bfd/srec.c in libdbfd in GNU binutils before 2.25 allows remote attackers to cause a denial of service (out-of-bounds read) via a small S-record.
Scope: local
bookworm: resolved (fixed in 2.24.51.20140903-1)
bullseye: resolved (fixed in 2.24.51.20140903-1)
forky: resolved (fixed in 2.24.51.20140903-1)
sid: resolved (fixed in 2.24.51.201409
debian
CVE-2014-8738MEDIUMCVSS 5.0fixed in binutils 2.24.90.20141124-1 (bookworm)2014
CVE-2014-8738 [MEDIUM] CVE-2014-8738: binutils - The _bfd_slurp_extended_name_table function in bfd/archive.c in GNU binutils 2.2...
The _bfd_slurp_extended_name_table function in bfd/archive.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (invalid write, segmentation fault, and crash) via a crafted extended name table in an archive.
Scope: local
bookworm: resolved (fixed in 2.24.90.20141124-1)
bullseye: resolved (fixed in 2.24.90.20141124-1)
forky: resolv
debian
CVE-2014-8737LOWCVSS 3.6fixed in binutils 2.24.90.20141124-1 (bookworm)2014
CVE-2014-8737 [LOW] CVE-2014-8737: binutils - Multiple directory traversal vulnerabilities in GNU binutils 2.24 and earlier al...
Multiple directory traversal vulnerabilities in GNU binutils 2.24 and earlier allow local users to delete arbitrary files via a .. (dot dot) or full path name in an archive to (1) strip or (2) objcopy or create arbitrary files via (3) a .. (dot dot) or full path name in an archive to ar.
Scope: local
bookworm: resolved (fixed in 2.24.90.20141124-1)
bullseye: resolved
debian
CVE-2012-3509LOWCVSS 5.0fixed in binutils 2.22-8 (bookworm)2012
CVE-2012-3509 [MEDIUM] CVE-2012-3509: binutils - Multiple integer overflows in the (1) _objalloc_alloc function in objalloc.c and...
Multiple integer overflows in the (1) _objalloc_alloc function in objalloc.c and (2) objalloc_alloc macro in include/objalloc.h in GNU libiberty, as used by binutils 2.22, allow remote attackers to cause a denial of service (crash) via vectors related to the "addition of CHUNK_HEADER_SIZE to the length," which triggers a heap-based buffer overflow.
Scope: local
boo
debian