cbcvebase.

Debian Binutils vulnerabilities

259 known vulnerabilities affecting debian/binutils.

Total CVEs
259
CISA KEV
0
Public exploits
12
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH40MEDIUM23LOW193

Vulnerabilities

Page 6 of 13
CVE-2018-7643P4HIGHCVSS 7.8fixed in binutils 2.30-6 (bookworm)2018
CVE-2018-7643 [HIGH] CVE-2018-7643: binutils - The display_debug_ranges function in dwarf.c in GNU Binutils 2.30 allows remote ... The display_debug_ranges function in dwarf.c in GNU Binutils 2.30 allows remote attackers to cause a denial of service (integer overflow and application crash) or possibly have unspecified other impact via a crafted ELF file, as demonstrated by objdump. Scope: local bookworm: resolved (fixed in 2.30-6) bullseye: resolved (fixed in 2.30-6) forky: resolved (fixed in 2.
debian
CVE-2018-6543P4HIGHCVSS 7.8fixed in binutils 2.30-3 (bookworm)2018
CVE-2018-6543 [HIGH] CVE-2018-6543: binutils - In GNU Binutils 2.30, there's an integer overflow in the function load_specific_... In GNU Binutils 2.30, there's an integer overflow in the function load_specific_debug_section() in objdump.c, which results in `malloc()` with 0 size. A crafted ELF file allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact. Scope: local bookworm: resolved (fixed in 2.30-3) bullseye: resolved (fixed in 2.30
debian
CVE-2017-16830P4LOWCVSS 7.8fixed in binutils 2.29.90.20180122-1 (bookworm)2017
CVE-2017-16830 [HIGH] CVE-2017-16830: binutils - The print_gnu_property_note function in readelf.c in GNU Binutils 2.29.1 does no... The print_gnu_property_note function in readelf.c in GNU Binutils 2.29.1 does not have integer-overflow protection on 32-bit platforms, which allows remote attackers to cause a denial of service (segmentation violation and application crash) or possibly have unspecified other impact via a crafted ELF file. Scope: local bookworm: resolved (fixed in 2.29.90.20180122-
debian
CVE-2017-9043P4LOWCVSS 7.8fixed in binutils 2.29-1 (bookworm)2017
CVE-2017-9043 [HIGH] CVE-2017-9043: binutils - readelf.c in GNU Binutils 2017-04-12 has a "shift exponent too large for type un... readelf.c in GNU Binutils 2017-04-12 has a "shift exponent too large for type unsigned long" issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted ELF file. Scope: local bookworm: resolved (fixed in 2.29-1) bullseye: resolved (fixed in 2.29-1) forky: resolved (fixed in 2.29-1
debian
CVE-2017-16826P4LOWCVSS 7.8fixed in binutils 2.29.90.20180122-1 (bookworm)2017
CVE-2017-16826 [HIGH] CVE-2017-16826: binutils - The coff_slurp_line_table function in coffcode.h in the Binary File Descriptor (... The coff_slurp_line_table function in coffcode.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, allows remote attackers to cause a denial of service (invalid memory access and application crash) or possibly have unspecified other impact via a crafted PE file. Scope: local bookworm: resolved (fixed in 2.29.90.2018012
debian
CVE-2017-16831P4LOWCVSS 7.8fixed in binutils 2.29.90.20180122-1 (bookworm)2017
CVE-2017-16831 [HIGH] CVE-2017-16831: binutils - coffgen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distribut... coffgen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, does not validate the symbol count, which allows remote attackers to cause a denial of service (integer overflow and application crash, or excessive memory allocation) or possibly have unspecified other impact via a crafted PE file. Scope: local bookworm: reso
debian
CVE-2017-17126P4LOWCVSS 7.8fixed in binutils 2.29.90.20180122-1 (bookworm)2017
CVE-2017-17126 [HIGH] CVE-2017-17126: binutils - The load_debug_section function in readelf.c in GNU Binutils 2.29.1 allows remot... The load_debug_section function in readelf.c in GNU Binutils 2.29.1 allows remote attackers to cause a denial of service (invalid memory access and application crash) or possibly have unspecified other impact via an ELF file that lacks section headers. Scope: local bookworm: resolved (fixed in 2.29.90.20180122-1) bullseye: resolved (fixed in 2.29.90.20180122-1) for
debian
CVE-2017-12456P4HIGHCVSS 7.8fixed in binutils 2.29-9 (bookworm)2017
CVE-2017-12456 [HIGH] CVE-2017-12456: binutils - The read_symbol_stabs_debugging_info function in rddbg.c in GNU Binutils 2.29 an... The read_symbol_stabs_debugging_info function in rddbg.c in GNU Binutils 2.29 and earlier allows remote attackers to cause an out of bounds heap read via a crafted binary file. Scope: local bookworm: resolved (fixed in 2.29-9) bullseye: resolved (fixed in 2.29-9) forky: resolved (fixed in 2.29-9) sid: resolved (fixed in 2.29-9) trixie: resolved (fixed in 2.29-9)
debian
CVE-2017-12449P4HIGHCVSS 7.8fixed in binutils 2.29-8 (bookworm)2017
CVE-2017-12449 [HIGH] CVE-2017-12449: binutils - The _bfd_vms_save_sized_string function in vms-misc.c in the Binary File Descrip... The _bfd_vms_save_sized_string function in vms-misc.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an out of bounds heap read via a crafted vms file. Scope: local bookworm: resolved (fixed in 2.29-8) bullseye: resolved (fixed in 2.29-8) forky: resolved (fixed in 2.29-8) s
debian
CVE-2022-47673P4LOWCVSS 7.8fixed in binutils 2.39.50.20221224-1 (bookworm)2022
CVE-2022-47673 [HIGH] CVE-2022-47673: binutils - An issue was discovered in Binutils addr2line before 2.39.3, function parse_modu... An issue was discovered in Binutils addr2line before 2.39.3, function parse_module contains multiple out of bound reads which may cause a denial of service or other unspecified impacts. Scope: local bookworm: resolved (fixed in 2.39.50.20221224-1) bullseye: open forky: resolved (fixed in 2.39.50.20221224-1) sid: resolved (fixed in 2.39.50.20221224-1) trixie: resolv
debian
CVE-2017-9042P4LOWCVSS 7.8fixed in binutils 2.29-1 (bookworm)2017
CVE-2017-9042 [HIGH] CVE-2017-9042: binutils - readelf.c in GNU Binutils 2017-04-12 has a "cannot be represented in type long" ... readelf.c in GNU Binutils 2017-04-12 has a "cannot be represented in type long" issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted ELF file. Scope: local bookworm: resolved (fixed in 2.29-1) bullseye: resolved (fixed in 2.29-1) forky: resolved (fixed in 2.29-1) sid: resolv
debian
CVE-2017-17125P4LOWCVSS 7.8fixed in binutils 2.29.90.20180122-1 (bookworm)2017
CVE-2017-17125 [HIGH] CVE-2017-17125: binutils - nm.c and objdump.c in GNU Binutils 2.29.1 mishandle certain global symbols, whic... nm.c and objdump.c in GNU Binutils 2.29.1 mishandle certain global symbols, which allows remote attackers to cause a denial of service (_bfd_elf_get_symbol_version_string buffer over-read and application crash) or possibly have unspecified other impact via a crafted ELF file. Scope: local bookworm: resolved (fixed in 2.29.90.20180122-1) bullseye: resolved (fixed in
debian
CVE-2017-14333P4HIGHCVSS 7.8fixed in binutils 2.29-9 (bookworm)2017
CVE-2017-14333 [HIGH] CVE-2017-14333: binutils - The process_version_sections function in readelf.c in GNU Binutils 2.29 allows a... The process_version_sections function in readelf.c in GNU Binutils 2.29 allows attackers to cause a denial of service (Integer Overflow, and hang because of a time-consuming loop) or possibly have unspecified other impact via a crafted binary file with invalid values of ent.vn_next, during "readelf -a" execution. Scope: local bookworm: resolved (fixed in 2.29-9) bu
debian
CVE-2022-47695P4LOWCVSS 7.8fixed in binutils 2.39.50.20221208-2 (bookworm)2022
CVE-2022-47695 [HIGH] CVE-2022-47695: binutils - An issue was discovered Binutils objdump before 2.39.3 allows attackers to cause... An issue was discovered Binutils objdump before 2.39.3 allows attackers to cause a denial of service or other unspecified impacts via function bfd_mach_o_get_synthetic_symtab in match-o.c. Scope: local bookworm: resolved (fixed in 2.39.50.20221208-2) bullseye: open forky: resolved (fixed in 2.39.50.20221208-2) sid: resolved (fixed in 2.39.50.20221208-2) trixie: res
debian
CVE-2025-1153P4LOWCVSS 2.3fixed in binutils 2.45-3 (forky)2025
CVE-2025-1153 [LOW] CVE-2025-1153: binutils - A vulnerability classified as problematic was found in GNU Binutils 2.43/2.44. A... A vulnerability classified as problematic was found in GNU Binutils 2.43/2.44. Affected by this vulnerability is the function bfd_set_format of the file format.c. The manipulation leads to memory corruption. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. Upgrading to version 2.45 is able to ad
debian
CVE-2023-1972P4LOWCVSS 6.5fixed in binutils 2.41-1 (forky)2023
CVE-2023-1972 [MEDIUM] CVE-2023-1972: binutils - A potential heap based buffer overflow was found in _bfd_elf_slurp_version_table... A potential heap based buffer overflow was found in _bfd_elf_slurp_version_tables() in bfd/elf.c. This may lead to loss of availability. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 2.41-1) sid: resolved (fixed in 2.41-1) trixie: resolved (fixed in 2.41-1)
debian
CVE-2017-14745P4HIGHCVSS 7.8fixed in binutils 2.29-11 (bookworm)2017
CVE-2017-14745 [HIGH] CVE-2017-14745: binutils - The *_get_synthetic_symtab functions in the Binary File Descriptor (BFD) library... The *_get_synthetic_symtab functions in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, interpret a -1 value as a sorting count instead of an error flag, which allows remote attackers to cause a denial of service (integer overflow and application crash) or possibly have unspecified other impact via a crafted ELF file, rel
debian
CVE-2022-47696P4LOWCVSS 7.8fixed in binutils 2.39.50.20221208-2 (bookworm)2022
CVE-2022-47696 [HIGH] CVE-2022-47696: binutils - An issue was discovered Binutils objdump before 2.39.3 allows attackers to cause... An issue was discovered Binutils objdump before 2.39.3 allows attackers to cause a denial of service or other unspecified impacts via function compare_symbols. Scope: local bookworm: resolved (fixed in 2.39.50.20221208-2) bullseye: open forky: resolved (fixed in 2.39.50.20221208-2) sid: resolved (fixed in 2.39.50.20221208-2) trixie: resolved (fixed in 2.39.50.20221
debian
CVE-2021-3549P4LOWCVSS 7.1fixed in binutils 2.37-3 (bookworm)2021
CVE-2021-3549 [HIGH] CVE-2021-3549: binutils - An out of bounds flaw was found in GNU binutils objdump utility version 2.36. An... An out of bounds flaw was found in GNU binutils objdump utility version 2.36. An attacker could use this flaw and pass a large section to avr_elf32_load_records_from_section() probably resulting in a crash or in some cases memory corruption. The highest threat from this vulnerability is to integrity as well as system availability. Scope: local bookworm: resolved (fix
debian
CVE-2019-17451P4LOWCVSS 6.5fixed in binutils 2.34-1 (bookworm)2019
CVE-2019-17451 [MEDIUM] CVE-2019-17451: binutils - An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd)... An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is an integer overflow leading to a SEGV in _bfd_dwarf2_find_nearest_line in dwarf2.c, as demonstrated by nm. Scope: local bookworm: resolved (fixed in 2.34-1) bullseye: resolved (fixed in 2.34-1) forky: resolved (fixed in 2.34-1) sid: resolve
debian
Debian Binutils vulnerabilities | cvebase