cbcvebase.

Debian Binutils vulnerabilities

259 known vulnerabilities affecting debian/binutils.

Total CVEs
259
CISA KEV
0
Public exploits
12
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH40MEDIUM23LOW193

Vulnerabilities

Page 4 of 13
CVE-2017-17122P4LOWCVSS 7.8fixed in binutils 2.29.90.20180122-1 (bookworm)2017
CVE-2017-17122 [HIGH] CVE-2017-17122: binutils - The dump_relocs_in_section function in objdump.c in GNU Binutils 2.29.1 does not... The dump_relocs_in_section function in objdump.c in GNU Binutils 2.29.1 does not check for reloc count integer overflows, which allows remote attackers to cause a denial of service (excessive memory allocation, or heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted PE file. Scope: local bookworm: resolved (fixed
debian
CVE-2019-9070P4LOWCVSS 7.8fixed in binutils 2.32.51.20190707-1 (bookworm)2019
CVE-2019-9070 [HIGH] CVE-2019-9070: binutils - An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. I... An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. It is a heap-based buffer over-read in d_expression_1 in cp-demangle.c after many recursive calls. Scope: local bookworm: resolved (fixed in 2.32.51.20190707-1) bullseye: resolved (fixed in 2.32.51.20190707-1) forky: resolved (fixed in 2.32.51.20190707-1) sid: resolved (fixed in 2.32.51.20
debian
CVE-2017-7301P4HIGHCVSS 7.5fixed in binutils 2.27.51.20161212-1 (bookworm)2017
CVE-2017-7301 [HIGH] CVE-2017-7301: binutils - The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Bin... The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has an aout_link_add_symbols function in bfd/aoutx.h that has an off-by-one vulnerability because it does not carefully check the string offset. The vulnerability could lead to a GNU linker (ld) program crash. Scope: local bookworm: resolved (fixed in 2.27.51.20161212-1) bulls
debian
CVE-2017-8395P4HIGHCVSS 7.5fixed in binutils 2.28-5 (bookworm)2017
CVE-2017-8395 [HIGH] CVE-2017-8395: binutils - The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Bin... The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid write of size 8 because of missing a malloc() return-value check to see if memory had actually been allocated in the _bfd_generic_get_section_contents function. This vulnerability causes programs that conduct an analysis of binary programs using the
debian
CVE-2022-45703P4LOWCVSS 7.8fixed in binutils 2.40-2 (bookworm)2022
CVE-2022-45703 [HIGH] CVE-2022-45703: binutils - Heap buffer overflow vulnerability in binutils readelf before 2.40 via function ... Heap buffer overflow vulnerability in binutils readelf before 2.40 via function display_debug_section in file readelf.c. Scope: local bookworm: resolved (fixed in 2.40-2) bullseye: open forky: resolved (fixed in 2.40-2) sid: resolved (fixed in 2.40-2) trixie: resolved (fixed in 2.40-2)
debian
CVE-2023-1579P3LOWCVSS 7.8fixed in binutils 2.40-2 (bookworm)2023
CVE-2023-1579 [HIGH] CVE-2023-1579: binutils - Heap based buffer overflow in binutils-gdb/bfd/libbfd.c in bfd_getl64. Heap based buffer overflow in binutils-gdb/bfd/libbfd.c in bfd_getl64. Scope: local bookworm: resolved (fixed in 2.40-2) bullseye: open forky: resolved (fixed in 2.40-2) sid: resolved (fixed in 2.40-2) trixie: resolved (fixed in 2.40-2)
debian
CVE-2022-44840P4LOWCVSS 7.8fixed in binutils 2.40-2 (bookworm)2022
CVE-2022-44840 [HIGH] CVE-2022-44840: binutils - Heap buffer overflow vulnerability in binutils readelf before 2.40 via function ... Heap buffer overflow vulnerability in binutils readelf before 2.40 via function find_section_in_set in file readelf.c. Scope: local bookworm: resolved (fixed in 2.40-2) bullseye: open forky: resolved (fixed in 2.40-2) sid: resolved (fixed in 2.40-2) trixie: resolved (fixed in 2.40-2)
debian
CVE-2017-12799P4HIGHCVSS 7.8fixed in binutils 2.29-9 (bookworm)2017
CVE-2017-12799 [HIGH] CVE-2017-12799: binutils - The elf_read_notesfunction in bfd/elf.c in GNU Binutils 2.29 allows remote attac... The elf_read_notesfunction in bfd/elf.c in GNU Binutils 2.29 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file. Scope: local bookworm: resolved (fixed in 2.29-9) bullseye: resolved (fixed in 2.29-9) forky: resolved (fixed in 2.29-9) sid: resolved (fixed in
debian
CVE-2017-9755P4LOWCVSS 7.8fixed in binutils 2.29-1 (bookworm)2017
CVE-2017-9755 [HIGH] CVE-2017-9755: binutils - opcodes/i386-dis.c in GNU Binutils 2.28 does not consider the number of register... opcodes/i386-dis.c in GNU Binutils 2.28 does not consider the number of registers for bnd mode, which allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by mishandling of this file during "objdump -D" execution. Scope: local bookworm: resolve
debian
CVE-2017-9754P4LOWCVSS 7.8fixed in binutils 2.29-1 (bookworm)2017
CVE-2017-9754 [HIGH] CVE-2017-9754: binutils - The process_otr function in bfd/versados.c in the Binary File Descriptor (BFD) l... The process_otr function in bfd/versados.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, does not validate a certain offset, which allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by mishandl
debian
CVE-2018-18483P4LOWCVSS 7.8fixed in binutils 2.32.51.20190707-1 (bookworm)2018
CVE-2018-18483 [HIGH] CVE-2018-18483: binutils - The get_count function in cplus-dem.c in GNU libiberty, as distributed in GNU Bi... The get_count function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31, allows remote attackers to cause a denial of service (malloc called with the result of an integer-overflowing calculation) or possibly have unspecified other impact via a crafted string, as demonstrated by c++filt. Scope: local bookworm: resolved (fixed in 2.32.51.20190707-
debian
CVE-2017-15996P4LOWCVSS 7.8fixed in binutils 2.29.90.20180122-1 (bookworm)2017
CVE-2017-15996 [HIGH] CVE-2017-15996: binutils - elfcomm.c in readelf in GNU Binutils 2.29 allows remote attackers to cause a den... elfcomm.c in readelf in GNU Binutils 2.29 allows remote attackers to cause a denial of service (excessive memory allocation) or possibly have unspecified other impact via a crafted ELF file that triggers a "buffer overflow on fuzzed archive header," related to an uninitialized variable, an improper conditional jump, and the get_archive_member_name, process_archive_
debian
CVE-2017-15020P4LOWCVSS 7.8fixed in binutils 2.29.90.20180122-1 (bookworm)2017
CVE-2017-15020 [HIGH] CVE-2017-15020: binutils - dwarf1.c in the Binary File Descriptor (BFD) library (aka libbfd), as distribute... dwarf1.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, mishandles pointers, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted ELF file, related to parse_die and parse_line_table, as demonstrated by a parse_die heap-based buffer over-
debian
CVE-2017-16828P4LOWCVSS 7.8fixed in binutils 2.29.90.20180122-1 (bookworm)2017
CVE-2017-16828 [HIGH] CVE-2017-16828: binutils - The display_debug_frames function in dwarf.c in GNU Binutils 2.29.1 allows remot... The display_debug_frames function in dwarf.c in GNU Binutils 2.29.1 allows remote attackers to cause a denial of service (integer overflow and heap-based buffer over-read, and application crash) or possibly have unspecified other impact via a crafted ELF file, related to print_debug_frame. Scope: local bookworm: resolved (fixed in 2.29.90.20180122-1) bullseye: reso
debian
CVE-2017-7225P4HIGHCVSS 7.5fixed in binutils 2.27.51.20161201-1 (bookworm)2017
CVE-2017-7225 [HIGH] CVE-2017-7225: binutils - The find_nearest_line function in addr2line in GNU Binutils 2.28 does not handle... The find_nearest_line function in addr2line in GNU Binutils 2.28 does not handle the case where the main file name and the directory name are both empty, triggering a NULL pointer dereference and an invalid write, and leading to a program crash. Scope: local bookworm: resolved (fixed in 2.27.51.20161201-1) bullseye: resolved (fixed in 2.27.51.20161201-1) forky: resol
debian
CVE-2017-8398P4HIGHCVSS 7.5fixed in binutils 2.28-5 (bookworm)2017
CVE-2017-8398 [HIGH] CVE-2017-8398: binutils - dwarf.c in GNU Binutils 2.28 is vulnerable to an invalid read of size 1 during d... dwarf.c in GNU Binutils 2.28 is vulnerable to an invalid read of size 1 during dumping of debug information from a corrupt binary. This vulnerability causes programs that conduct an analysis of binary programs, such as objdump and readelf, to crash. Scope: local bookworm: resolved (fixed in 2.28-5) bullseye: resolved (fixed in 2.28-5) forky: resolved (fixed in 2.28-5
debian
CVE-2017-7223P4HIGHCVSS 7.5fixed in binutils 2.27.51.20161212-1 (bookworm)2017
CVE-2017-7223 [HIGH] CVE-2017-7223: binutils - GNU assembler in GNU Binutils 2.28 is vulnerable to a global buffer overflow (of... GNU assembler in GNU Binutils 2.28 is vulnerable to a global buffer overflow (of size 1) while attempting to unget an EOF character from the input stream, potentially leading to a program crash. Scope: local bookworm: resolved (fixed in 2.27.51.20161212-1) bullseye: resolved (fixed in 2.27.51.20161212-1) forky: resolved (fixed in 2.27.51.20161212-1) sid: resolved (fi
debian
CVE-2017-8394P4HIGHCVSS 7.5fixed in binutils 2.28-5 (bookworm)2017
CVE-2017-8394 [HIGH] CVE-2017-8394: binutils - The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Bin... The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid read of size 4 due to NULL pointer dereferencing of _bfd_elf_large_com_section. This vulnerability causes programs that conduct an analysis of binary programs using the libbfd library, such as objcopy, to crash. Scope: local bookworm: resolved (fixe
debian
CVE-2017-15938P4LOWCVSS 7.5fixed in binutils 2.29.90.20180122-1 (bookworm)2017
CVE-2017-15938 [HIGH] CVE-2017-15938: binutils - dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distribute... dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, miscalculates DW_FORM_ref_addr die refs in the case of a relocatable object file, which allows remote attackers to cause a denial of service (find_abstract_instance_name invalid memory read, segmentation fault, and application crash). Scope: local bookworm: resol
debian
CVE-2025-1178P4LOWCVSS 6.3fixed in binutils 2.45-3 (forky)2025
CVE-2025-1178 [MEDIUM] CVE-2025-1178: binutils - A vulnerability was found in GNU Binutils 2.43. It has been declared as problema... A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. Affected by this vulnerability is the function bfd_putl64 of the file libbfd.c of the component ld. The manipulation leads to memory corruption. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit ha
debian
Debian Binutils vulnerabilities | cvebase