cbcvebase.

Debian Binutils vulnerabilities

285 known vulnerabilities affecting debian/binutils.

Total CVEs
285
CISA KEV
0
Public exploits
12
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH40MEDIUM23LOW219

Vulnerabilities

Page 6 of 15
CVE-2019-9075LOWCVSS 7.8fixed in binutils 2.32.51.20190707-1 (bookworm)2019
CVE-2019-9075 [HIGH] CVE-2019-9075: binutils - An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd)... An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is a heap-based buffer overflow in _bfd_archive_64_bit_slurp_armap in archive64.c. Scope: local bookworm: resolved (fixed in 2.32.51.20190707-1) bullseye: resolved (fixed in 2.32.51.20190707-1) forky: resolved (fixed in 2.32.51.20190707-1) sid: re
debian
CVE-2019-9077LOWCVSS 7.8fixed in binutils 2.32.51.20190707-1 (bookworm)2019
CVE-2019-9077 [HIGH] CVE-2019-9077: binutils - An issue was discovered in GNU Binutils 2.32. It is a heap-based buffer overflow... An issue was discovered in GNU Binutils 2.32. It is a heap-based buffer overflow in process_mips_specific in readelf.c via a malformed MIPS option section. Scope: local bookworm: resolved (fixed in 2.32.51.20190707-1) bullseye: resolved (fixed in 2.32.51.20190707-1) forky: resolved (fixed in 2.32.51.20190707-1) sid: resolved (fixed in 2.32.51.20190707-1) trixie: reso
debian
CVE-2019-9074LOWCVSS 5.5fixed in binutils 2.32.51.20190707-1 (bookworm)2019
CVE-2019-9074 [MEDIUM] CVE-2019-9074: binutils - An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd)... An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is an out-of-bounds read leading to a SEGV in bfd_getl32 in libbfd.c, when called from pex64_get_runtime_function in pei-x86_64.c. Scope: local bookworm: resolved (fixed in 2.32.51.20190707-1) bullseye: resolved (fixed in 2.32.51.20190707-1) for
debian
CVE-2019-9073LOWCVSS 5.5fixed in binutils 2.32.51.20190707-1 (bookworm)2019
CVE-2019-9073 [MEDIUM] CVE-2019-9073: binutils - An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd)... An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is an attempted excessive memory allocation in _bfd_elf_slurp_version_tables in elf.c. Scope: local bookworm: resolved (fixed in 2.32.51.20190707-1) bullseye: resolved (fixed in 2.32.51.20190707-1) forky: resolved (fixed in 2.32.51.20190707-1) s
debian
CVE-2019-9070LOWCVSS 7.8fixed in binutils 2.32.51.20190707-1 (bookworm)2019
CVE-2019-9070 [HIGH] CVE-2019-9070: binutils - An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. I... An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. It is a heap-based buffer over-read in d_expression_1 in cp-demangle.c after many recursive calls. Scope: local bookworm: resolved (fixed in 2.32.51.20190707-1) bullseye: resolved (fixed in 2.32.51.20190707-1) forky: resolved (fixed in 2.32.51.20190707-1) sid: resolved (fixed in 2.32.51.20
debian
CVE-2019-1010180LOWCVSS 7.8fixed in binutils 2.32.51.20190707-1 (bookworm)2019
CVE-2019-1010180 [HIGH] CVE-2019-1010180: binutils - GNU gdb All versions is affected by: Buffer Overflow - Out of bound memory acces... GNU gdb All versions is affected by: Buffer Overflow - Out of bound memory access. The impact is: Deny of Service, Memory Disclosure, and Possible Code Execution. The component is: The main gdb module. The attack vector is: Open an ELF for debugging. The fixed version is: Not fixed yet. Scope: local bookworm: resolved (fixed in 2.32.51.20190707-1) bullseye: res
debian
CVE-2019-14444LOWCVSS 5.5fixed in binutils 2.32.51.20190813-1 (bookworm)2019
CVE-2019-14444 [MEDIUM] CVE-2019-14444: binutils - apply_relocations in readelf.c in GNU Binutils 2.32 contains an integer overflow... apply_relocations in readelf.c in GNU Binutils 2.32 contains an integer overflow that allows attackers to trigger a write access violation (in byte_put_little_endian function in elfcomm.c) via an ELF file, as demonstrated by readelf. Scope: local bookworm: resolved (fixed in 2.32.51.20190813-1) bullseye: resolved (fixed in 2.32.51.20190813-1) forky: resolved (fix
debian
CVE-2019-14250LOWCVSS 5.5fixed in binutils 2.33-1 (bookworm)2019
CVE-2019-14250 [MEDIUM] CVE-2019-14250: binutils - An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. s... An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. simple_object_elf_match in simple-object-elf.c does not check for a zero shstrndx value, leading to an integer overflow and resultant heap-based buffer overflow. Scope: local bookworm: resolved (fixed in 2.33-1) bullseye: resolved (fixed in 2.33-1) forky: resolved (fixed in 2.33-1) sid
debian
CVE-2019-17451LOWCVSS 6.5fixed in binutils 2.34-1 (bookworm)2019
CVE-2019-17451 [MEDIUM] CVE-2019-17451: binutils - An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd)... An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is an integer overflow leading to a SEGV in _bfd_dwarf2_find_nearest_line in dwarf2.c, as demonstrated by nm. Scope: local bookworm: resolved (fixed in 2.34-1) bullseye: resolved (fixed in 2.34-1) forky: resolved (fixed in 2.34-1) sid: resolve
debian
CVE-2019-17450LOWCVSS 6.5fixed in binutils 2.34-1 (bookworm)2019
CVE-2019-17450 [MEDIUM] CVE-2019-17450: binutils - find_abstract_instance in dwarf2.c in the Binary File Descriptor (BFD) library (... find_abstract_instance in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32, allows remote attackers to cause a denial of service (infinite recursion and application crash) via a crafted ELF file. Scope: local bookworm: resolved (fixed in 2.34-1) bullseye: resolved (fixed in 2.34-1) forky: resolved (fixed in 2.
debian
CVE-2019-9071LOWCVSS 5.5fixed in binutils 2.32.51.20190707-1 (bookworm)2019
CVE-2019-9071 [MEDIUM] CVE-2019-9071: binutils - An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. I... An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. It is a stack consumption issue in d_count_templates_scopes in cp-demangle.c after many recursive calls. Scope: local bookworm: resolved (fixed in 2.32.51.20190707-1) bullseye: resolved (fixed in 2.32.51.20190707-1) forky: resolved (fixed in 2.32.51.20190707-1) sid: resolved (fixed in 2.
debian
CVE-2019-12972LOWCVSS 5.5fixed in binutils 2.32.51.20190707-1 (bookworm)2019
CVE-2019-12972 [MEDIUM] CVE-2019-12972: binutils - An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd)... An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. There is a heap-based buffer over-read in _bfd_doprnt in bfd.c because elf_object_p in elfcode.h mishandles an e_shstrndx section of type SHT_GROUP by omitting a trailing '\0' character. Scope: local bookworm: resolved (fixed in 2.32.51.20190707-
debian
CVE-2018-7643HIGHCVSS 7.8fixed in binutils 2.30-6 (bookworm)2018
CVE-2018-7643 [HIGH] CVE-2018-7643: binutils - The display_debug_ranges function in dwarf.c in GNU Binutils 2.30 allows remote ... The display_debug_ranges function in dwarf.c in GNU Binutils 2.30 allows remote attackers to cause a denial of service (integer overflow and application crash) or possibly have unspecified other impact via a crafted ELF file, as demonstrated by objdump. Scope: local bookworm: resolved (fixed in 2.30-6) bullseye: resolved (fixed in 2.30-6) forky: resolved (fixed in 2.
debian
CVE-2018-7208HIGHCVSS 7.8fixed in binutils 2.30-6 (bookworm)2018
CVE-2018-7208 [HIGH] CVE-2018-7208: binutils - In the coff_pointerize_aux function in coffgen.c in the Binary File Descriptor (... In the coff_pointerize_aux function in coffgen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, an index is not validated, which allows remote attackers to cause a denial of service (segmentation fault) or possibly have unspecified other impact via a crafted file, as demonstrated by objcopy of a COFF object. Scope: loca
debian
CVE-2018-6543HIGHCVSS 7.8fixed in binutils 2.30-3 (bookworm)2018
CVE-2018-6543 [HIGH] CVE-2018-6543: binutils - In GNU Binutils 2.30, there's an integer overflow in the function load_specific_... In GNU Binutils 2.30, there's an integer overflow in the function load_specific_debug_section() in objdump.c, which results in `malloc()` with 0 size. A crafted ELF file allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact. Scope: local bookworm: resolved (fixed in 2.30-3) bullseye: resolved (fixed in 2.30
debian
CVE-2018-6323HIGHCVSS 7.8PoCfixed in binutils 2.30-3 (bookworm)2018
CVE-2018-6323 [HIGH] CVE-2018-6323: binutils - The elf_object_p function in elfcode.h in the Binary File Descriptor (BFD) libra... The elf_object_p function in elfcode.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, has an unsigned integer overflow because bfd_size_type multiplication is not used. A crafted ELF file allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact. Scope: local bo
debian
CVE-2018-10534MEDIUMCVSS 5.5fixed in binutils 2.30.90.20180627-1 (bookworm)2018
CVE-2018-10534 [MEDIUM] CVE-2018-10534: binutils - The _bfd_XX_bfd_copy_private_bfd_data_common function in peXXigen.c in the Binar... The _bfd_XX_bfd_copy_private_bfd_data_common function in peXXigen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, processes a negative Data Directory size with an unbounded loop that increases the value of (external_IMAGE_DEBUG_DIRECTORY) *edd so that the address exceeds its own memory region, resulting in an out-o
debian
CVE-2018-10535MEDIUMCVSS 5.5fixed in binutils 2.30.90.20180627-1 (bookworm)2018
CVE-2018-10535 [MEDIUM] CVE-2018-10535: binutils - The ignore_section_sym function in elf.c in the Binary File Descriptor (BFD) lib... The ignore_section_sym function in elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, does not validate the output_section pointer in the case of a symtab entry with a "SECTION" type that has a "0" value, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) vi
debian
CVE-2018-7642MEDIUMCVSS 5.5fixed in binutils 2.30-6 (bookworm)2018
CVE-2018-7642 [MEDIUM] CVE-2018-7642: binutils - The swap_std_reloc_in function in aoutx.h in the Binary File Descriptor (BFD) li... The swap_std_reloc_in function in aoutx.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to cause a denial of service (aout_32_swap_std_reloc_out NULL pointer dereference and application crash) via a crafted ELF file, as demonstrated by objcopy. Scope: local bookworm: resolved (fixed in 2.30-6)
debian
CVE-2018-10373MEDIUMCVSS 6.5fixed in binutils 2.30.90.20180627-1 (bookworm)2018
CVE-2018-10373 [MEDIUM] CVE-2018-10373: binutils - concat_filename in dwarf2.c in the Binary File Descriptor (BFD) library (aka lib... concat_filename in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted binary file, as demonstrated by nm-new. Scope: local bookworm: resolved (fixed in 2.30.90.20180627-1) bullseye: resolved (fixe
debian