Debian Binutils vulnerabilities
259 known vulnerabilities affecting debian/binutils.
Total CVEs
259
CISA KEV
0
Public exploits
12
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH40MEDIUM23LOW193
Vulnerabilities
Page 3 of 13
CVE-2020-19726P3LOWCVSS 8.8fixed in binutils 2.37-3 (bookworm)2020
CVE-2020-19726 [HIGH] CVE-2020-19726: binutils - An issue was discovered in binutils libbfd.c 2.36 relating to the auxiliary symb...
An issue was discovered in binutils libbfd.c 2.36 relating to the auxiliary symbol data allows attackers to read or write to system memory or cause a denial of service.
Scope: local
bookworm: resolved (fixed in 2.37-3)
bullseye: open
forky: resolved (fixed in 2.37-3)
sid: resolved (fixed in 2.37-3)
trixie: resolved (fixed in 2.37-3)
debian
CVE-2018-12934P3LOWCVSS 7.5fixed in binutils 2.32.51.20190707-1 (bookworm)2018
CVE-2018-12934 [HIGH] CVE-2018-12934: binutils - remember_Ktype in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2...
remember_Ktype in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows attackers to trigger excessive memory consumption (aka OOM). This can occur during execution of cxxfilt.
Scope: local
bookworm: resolved (fixed in 2.32.51.20190707-1)
bullseye: resolved (fixed in 2.32.51.20190707-1)
forky: resolved (fixed in 2.32.51.20190707-1)
sid: resolved
debian
CVE-2017-12448P3HIGHCVSS 7.8fixed in binutils 2.29-9 (bookworm)2017
CVE-2017-12448 [HIGH] CVE-2017-12448: binutils - The bfd_cache_close function in bfd/cache.c in the Binary File Descriptor (BFD) ...
The bfd_cache_close function in bfd/cache.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause a heap use after free and possibly achieve code execution via a crafted nested archive file. This issue occurs because incorrect functions are called during an attempt to release memo
debian
CVE-2017-12459P3HIGHCVSS 7.8fixed in binutils 2.29-8 (bookworm)2017
CVE-2017-12459 [HIGH] CVE-2017-12459: binutils - The bfd_mach_o_read_symtab_strtab function in bfd/mach-o.c in the Binary File De...
The bfd_mach_o_read_symtab_strtab function in bfd/mach-o.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an out of bounds heap write and possibly achieve code execution via a crafted mach-o file.
Scope: local
bookworm: resolved (fixed in 2.29-8)
bullseye: resolved (fixed i
debian
CVE-2017-12450P3HIGHCVSS 7.8fixed in binutils 2.29-9 (bookworm)2017
CVE-2017-12450 [HIGH] CVE-2017-12450: binutils - The alpha_vms_object_p function in bfd/vms-alpha.c in the Binary File Descriptor...
The alpha_vms_object_p function in bfd/vms-alpha.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an out of bounds heap write and possibly achieve code execution via a crafted vms alpha file.
Scope: local
bookworm: resolved (fixed in 2.29-9)
bullseye: resolved (fixed in 2.2
debian
CVE-2017-7227P3HIGHCVSS 7.5fixed in binutils 2.27.51.20161212-1 (bookworm)2017
CVE-2017-7227 [HIGH] CVE-2017-7227: binutils - GNU linker (ld) in GNU Binutils 2.28 is vulnerable to a heap-based buffer overfl...
GNU linker (ld) in GNU Binutils 2.28 is vulnerable to a heap-based buffer overflow while processing a bogus input script, leading to a program crash. This relates to lack of '\0' termination of a name field in ldlex.l.
Scope: local
bookworm: resolved (fixed in 2.27.51.20161212-1)
bullseye: resolved (fixed in 2.27.51.20161212-1)
forky: resolved (fixed in 2.27.51.20161
debian
CVE-2019-9075P3LOWCVSS 7.8fixed in binutils 2.32.51.20190707-1 (bookworm)2019
CVE-2019-9075 [HIGH] CVE-2019-9075: binutils - An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd)...
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is a heap-based buffer overflow in _bfd_archive_64_bit_slurp_armap in archive64.c.
Scope: local
bookworm: resolved (fixed in 2.32.51.20190707-1)
bullseye: resolved (fixed in 2.32.51.20190707-1)
forky: resolved (fixed in 2.32.51.20190707-1)
sid: re
debian
CVE-2018-19931P3LOWCVSS 7.8fixed in binutils 2.32.51.20190707-1 (bookworm)2018
CVE-2018-19931 [HIGH] CVE-2018-19931: binutils - An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd)...
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils through 2.31. There is a heap-based buffer overflow in bfd_elf32_swap_phdr_in in elfcode.h because the number of program headers is not restricted.
Scope: local
bookworm: resolved (fixed in 2.32.51.20190707-1)
bullseye: resolved (fixed in 2.32.51.2019070
debian
CVE-2017-7304P3HIGHCVSS 7.5fixed in binutils 2.27.51.20161212-1 (bookworm)2017
CVE-2017-7304 [HIGH] CVE-2017-7304: binutils - The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Bin...
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid read (of size 8) because of missing a check (in the copy_special_section_fields function) for an invalid sh_link field before attempting to follow it. This vulnerability causes Binutils utilities like strip to crash.
Scope: local
bookworm: resolved
debian
CVE-2017-8397P3HIGHCVSS 7.5fixed in binutils 2.28-5 (bookworm)2017
CVE-2017-8397 [HIGH] CVE-2017-8397: binutils - The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Bin...
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid read of size 1 and an invalid write of size 1 during processing of a corrupt binary containing reloc(s) with negative addresses. This vulnerability causes programs that conduct an analysis of binary programs using the libbfd library, such as objdump
debian
CVE-2021-46174P3LOWCVSS 7.5fixed in binutils 2.37.90.20220207-1 (bookworm)2021
CVE-2021-46174 [HIGH] CVE-2021-46174: binutils - Heap-based Buffer Overflow in function bfd_getl32 in Binutils objdump 3.37.
Heap-based Buffer Overflow in function bfd_getl32 in Binutils objdump 3.37.
Scope: local
bookworm: resolved (fixed in 2.37.90.20220207-1)
bullseye: open
forky: resolved (fixed in 2.37.90.20220207-1)
sid: resolved (fixed in 2.37.90.20220207-1)
trixie: resolved (fixed in 2.37.90.20220207-1)
debian
CVE-2017-17124P3LOWCVSS 7.8fixed in binutils 2.29.90.20180122-1 (bookworm)2017
CVE-2017-17124 [HIGH] CVE-2017-17124: binutils - The _bfd_coff_read_string_table function in coffgen.c in the Binary File Descrip...
The _bfd_coff_read_string_table function in coffgen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, does not properly validate the size of the external string table, which allows remote attackers to cause a denial of service (excessive memory consumption, or heap-based buffer overflow and application crash) or poss
debian
CVE-2017-7302P3HIGHCVSS 7.5fixed in binutils 2.27.51.20161212-1 (bookworm)2017
CVE-2017-7302 [HIGH] CVE-2017-7302: binutils - The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Bin...
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has a swap_std_reloc_out function in bfd/aoutx.h that is vulnerable to an invalid read (of size 4) because of missing checks for relocs that could not be recognised. This vulnerability causes Binutils utilities like strip to crash.
Scope: local
bookworm: resolved (fixed in 2.2
debian
CVE-2017-7300P3HIGHCVSS 7.5fixed in binutils 2.27.51.20161212-1 (bookworm)2017
CVE-2017-7300 [HIGH] CVE-2017-7300: binutils - The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Bin...
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has an aout_link_add_symbols function in bfd/aoutx.h that is vulnerable to a heap-based buffer over-read (off-by-one) because of an incomplete check for invalid string offsets while loading symbols, leading to a GNU linker (ld) program crash.
Scope: local
bookworm: resolved (f
debian
CVE-2017-7303P3HIGHCVSS 7.5fixed in binutils 2.27.51.20161212-1 (bookworm)2017
CVE-2017-7303 [HIGH] CVE-2017-7303: binutils - The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Bin...
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid read (of size 4) because of missing a check (in the find_link function) for null headers before attempting to match them. This vulnerability causes Binutils utilities like strip to crash.
Scope: local
bookworm: resolved (fixed in 2.27.51.20161212-1)
debian
CVE-2017-8393P3HIGHCVSS 7.5fixed in binutils 2.28-5 (bookworm)2017
CVE-2017-8393 [HIGH] CVE-2017-8393: binutils - The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Bin...
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to a global buffer over-read error because of an assumption made by code that runs for objcopy and strip, that SHT_REL/SHR_RELA sections are always named starting with a .rel/.rela prefix. This vulnerability causes programs that conduct an analysis of binary prog
debian
CVE-2017-8396P3HIGHCVSS 7.5fixed in binutils 2.28-5 (bookworm)2017
CVE-2017-8396 [HIGH] CVE-2017-8396: binutils - The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Bin...
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid read of size 1 because the existing reloc offset range tests didn't catch small negative offsets less than the size of the reloc field. This vulnerability causes programs that conduct an analysis of binary programs using the libbfd library, such as
debian
CVE-2021-37322P3LOWCVSS 7.8fixed in binutils 2.27.51.20161102-1 (bookworm)2021
CVE-2021-37322 [HIGH] CVE-2021-37322: binutils - GCC c++filt v2.26 was discovered to contain a use-after-free vulnerability via t...
GCC c++filt v2.26 was discovered to contain a use-after-free vulnerability via the component cplus-dem.c.
Scope: local
bookworm: resolved (fixed in 2.27.51.20161102-1)
bullseye: resolved (fixed in 2.27.51.20161102-1)
forky: resolved (fixed in 2.27.51.20161102-1)
sid: resolved (fixed in 2.27.51.20161102-1)
trixie: resolved (fixed in 2.27.51.20161102-1)
debian
CVE-2021-45078P3LOWCVSS 9.8fixed in binutils 2.37.50.20220106-1 (bookworm)2021
CVE-2021-45078 [CRITICAL] CVE-2021-45078: binutils - stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers...
stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds write. NOTE: this issue exists because of an incorrect fix for CVE-2018-12699.
Scope: local
bookworm: resolved (fixed in 2.37.50.20220106-1)
bull
debian
CVE-2017-14729P4HIGHCVSS 7.8fixed in binutils 2.29.1-2 (bookworm)2017
CVE-2017-14729 [HIGH] CVE-2017-14729: binutils - The *_get_synthetic_symtab functions in the Binary File Descriptor (BFD) library...
The *_get_synthetic_symtab functions in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, do not ensure a unique PLT entry for a symbol, which allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted ELF file, related to e
debian