cbcvebase.

Debian Binutils vulnerabilities

259 known vulnerabilities affecting debian/binutils.

Total CVEs
259
CISA KEV
0
Public exploits
12
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH40MEDIUM23LOW193

Vulnerabilities

Page 7 of 13
CVE-2025-1176P4LOWCVSS 2.3fixed in binutils 2.45-3 (forky)2025
CVE-2025-1176 [LOW] CVE-2025-1176: binutils - A vulnerability was found in GNU Binutils 2.43 and classified as critical. This ... A vulnerability was found in GNU Binutils 2.43 and classified as critical. This issue affects the function _bfd_elf_gc_mark_rsec of the file elflink.c of the component ld. The manipulation leads to heap-based buffer overflow. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has bee
debian
CVE-2017-12967P4MEDIUMCVSS 6.5fixed in binutils 2.29-5 (bookworm)2017
CVE-2017-12967 [MEDIUM] CVE-2017-12967: binutils - The getsym function in tekhex.c in the Binary File Descriptor (BFD) library (aka... The getsym function in tekhex.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a malformed tekhex binary. Scope: local bookworm: resolved (fixed in 2.29-5) bullseye: resolved (fixed in 2.29-5) forky: resolve
debian
CVE-2014-8738P4MEDIUMCVSS 5.0fixed in binutils 2.24.90.20141124-1 (bookworm)2014
CVE-2014-8738 [MEDIUM] CVE-2014-8738: binutils - The _bfd_slurp_extended_name_table function in bfd/archive.c in GNU binutils 2.2... The _bfd_slurp_extended_name_table function in bfd/archive.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (invalid write, segmentation fault, and crash) via a crafted extended name table in an archive. Scope: local bookworm: resolved (fixed in 2.24.90.20141124-1) bullseye: resolved (fixed in 2.24.90.20141124-1) forky: resolv
debian
CVE-2014-8484P4MEDIUMCVSS 5.0fixed in binutils 2.24.51.20140903-1 (bookworm)2014
CVE-2014-8484 [MEDIUM] CVE-2014-8484: binutils - The srec_scan function in bfd/srec.c in libdbfd in GNU binutils before 2.25 allo... The srec_scan function in bfd/srec.c in libdbfd in GNU binutils before 2.25 allows remote attackers to cause a denial of service (out-of-bounds read) via a small S-record. Scope: local bookworm: resolved (fixed in 2.24.51.20140903-1) bullseye: resolved (fixed in 2.24.51.20140903-1) forky: resolved (fixed in 2.24.51.20140903-1) sid: resolved (fixed in 2.24.51.201409
debian
CVE-2012-3509P4LOWCVSS 5.0fixed in binutils 2.22-8 (bookworm)2012
CVE-2012-3509 [MEDIUM] CVE-2012-3509: binutils - Multiple integer overflows in the (1) _objalloc_alloc function in objalloc.c and... Multiple integer overflows in the (1) _objalloc_alloc function in objalloc.c and (2) objalloc_alloc macro in include/objalloc.h in GNU libiberty, as used by binutils 2.22, allow remote attackers to cause a denial of service (crash) via vectors related to the "addition of CHUNK_HEADER_SIZE to the length," which triggers a heap-based buffer overflow. Scope: local boo
debian
CVE-2005-4808P4LOWCVSS 7.6fixed in binutils 2.17-1 (bookworm)2005
CVE-2005-4808 [HIGH] CVE-2005-4808: binutils - Buffer overflow in reset_vars in config/tc-crx.c in the GNU as (gas) assembler i... Buffer overflow in reset_vars in config/tc-crx.c in the GNU as (gas) assembler in Free Software Foundation GNU Binutils before 20050714 allows user-assisted attackers to have an unknown impact via a crafted .s file. Scope: local bookworm: resolved (fixed in 2.17-1) bullseye: resolved (fixed in 2.17-1) forky: resolved (fixed in 2.17-1) sid: resolved (fixed in 2.17-1)
debian
CVE-2025-1147P4LOWCVSS 2.3fixed in binutils 2.45-3 (forky)2025
CVE-2025-1147 [LOW] CVE-2025-1147: binutils - A vulnerability has been found in GNU Binutils 2.43 and classified as problemati... A vulnerability has been found in GNU Binutils 2.43 and classified as problematic. Affected by this vulnerability is the function __sanitizer::internal_strlen of the file binutils/nm.c of the component nm. The manipulation of the argument const leads to buffer overflow. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation a
debian
CVE-2025-1182P4LOWCVSS 2.3fixed in binutils 2.45-3 (forky)2025
CVE-2025-1182 [LOW] CVE-2025-1182: binutils - A vulnerability, which was classified as critical, was found in GNU Binutils 2.4... A vulnerability, which was classified as critical, was found in GNU Binutils 2.43. Affected is the function bfd_elf_reloc_symbol_deleted_p of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The e
debian
CVE-2025-11495P4LOWCVSS 4.8fixed in binutils 2.46-1 (forky)2025
CVE-2025-11495 [MEDIUM] CVE-2025-11495: binutils - A vulnerability was determined in GNU Binutils 2.45. The affected element is the... A vulnerability was determined in GNU Binutils 2.45. The affected element is the function elf_x86_64_relocate_section of the file elf64-x86-64.c of the component Linker. This manipulation causes heap-based buffer overflow. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Patch name: 6b21c8b2ecfef5c95142cbc2c32f
debian
CVE-2018-17794P4LOWCVSS 6.5fixed in binutils 2.32.51.20190707-1 (bookworm)2018
CVE-2018-17794 [MEDIUM] CVE-2018-17794: binutils - An issue was discovered in cplus-dem.c in GNU libiberty, as distributed in GNU B... An issue was discovered in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31. There is a NULL pointer dereference in work_stuff_copy_to_from when called from iterate_demangle_function. Scope: local bookworm: resolved (fixed in 2.32.51.20190707-1) bullseye: resolved (fixed in 2.32.51.20190707-1) forky: resolved (fixed in 2.32.51.20190707-1) sid: re
debian
CVE-2021-3826P4LOWCVSS 6.5fixed in binutils 2.37.50.20220121-1 (bookworm)2021
CVE-2021-3826 [MEDIUM] CVE-2021-3826: binutils - Heap/stack buffer overflow in the dlang_lname function in d-demangle.c in libibe... Heap/stack buffer overflow in the dlang_lname function in d-demangle.c in libiberty allows attackers to potentially cause a denial of service (segmentation fault and crash) via a crafted mangled symbol. Scope: local bookworm: resolved (fixed in 2.37.50.20220121-1) bullseye: open forky: resolved (fixed in 2.37.50.20220121-1) sid: resolved (fixed in 2.37.50.20220121-
debian
CVE-2023-25584P4LOWCVSS 6.3fixed in binutils 2.39.50.20221224-1 (bookworm)2023
CVE-2023-25584 [MEDIUM] CVE-2023-25584: binutils - An out-of-bounds read flaw was found in the parse_module function in bfd/vms-alp... An out-of-bounds read flaw was found in the parse_module function in bfd/vms-alpha.c in Binutils. Scope: local bookworm: resolved (fixed in 2.39.50.20221224-1) bullseye: open forky: resolved (fixed in 2.39.50.20221224-1) sid: resolved (fixed in 2.39.50.20221224-1) trixie: resolved (fixed in 2.39.50.20221224-1)
debian
CVE-2018-10373P4MEDIUMCVSS 6.5fixed in binutils 2.30.90.20180627-1 (bookworm)2018
CVE-2018-10373 [MEDIUM] CVE-2018-10373: binutils - concat_filename in dwarf2.c in the Binary File Descriptor (BFD) library (aka lib... concat_filename in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted binary file, as demonstrated by nm-new. Scope: local bookworm: resolved (fixed in 2.30.90.20180627-1) bullseye: resolved (fixe
debian
CVE-2008-2310P4LOWCVSS 6.8fixed in binutils 2.18.1~cvs20080103-1 (bookworm)2008
CVE-2008-2310 [MEDIUM] CVE-2008-2310: binutils - Format string vulnerability in c++filt in Apple Mac OS X 10.5 before 10.5.4 allo... Format string vulnerability in c++filt in Apple Mac OS X 10.5 before 10.5.4 allows user-assisted attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted string in (1) C++ or (2) Java source code. Scope: local bookworm: resolved (fixed in 2.18.1~cvs20080103-1) bullseye: resolved (fixed in 2.18.1~cvs20080103-1) forky: resolv
debian
CVE-2025-1181P4LOWCVSS 2.3fixed in binutils 2.45-3 (forky)2025
CVE-2025-1181 [LOW] CVE-2025-1181: binutils - A vulnerability classified as critical was found in GNU Binutils 2.43. This vuln... A vulnerability classified as critical was found in GNU Binutils 2.43. This vulnerability affects the function _bfd_elf_gc_mark_rsec of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been
debian
CVE-2025-11839P4LOWCVSS 4.8fixed in binutils 2.46-1 (forky)2025
CVE-2025-11839 [MEDIUM] CVE-2025-11839: binutils - A security flaw has been discovered in GNU Binutils 2.45. Impacted is the functi... A security flaw has been discovered in GNU Binutils 2.45. Impacted is the function tg_tag_type of the file prdbg.c. Performing a manipulation results in unchecked return value. The attack needs to be approached locally. The exploit has been released to the public and may be used for attacks. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 2.4
debian
CVE-2025-11412P4LOWCVSS 4.8fixed in binutils 2.46-1 (forky)2025
CVE-2025-11412 [MEDIUM] CVE-2025-11412: binutils - A vulnerability has been found in GNU Binutils 2.45. This impacts the function b... A vulnerability has been found in GNU Binutils 2.45. This impacts the function bfd_elf_gc_record_vtentry of the file bfd/elflink.c of the component Linker. The manipulation leads to out-of-bounds read. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The identifier of the patch is 047435dd988a3975d40c
debian
CVE-2020-35494P4LOWCVSS 6.1fixed in binutils 2.33.50.20200107-1 (bookworm)2020
CVE-2020-35494 [MEDIUM] CVE-2020-35494: binutils - There's a flaw in binutils /opcodes/tic4x-dis.c. An attacker who is able to subm... There's a flaw in binutils /opcodes/tic4x-dis.c. An attacker who is able to submit a crafted input file to be processed by binutils could cause usage of uninitialized memory. The highest threat is to application availability with a lower threat to data confidentiality. This flaw affects binutils versions prior to 2.34. Scope: local bookworm: resolved (fixed in 2.
debian
CVE-2018-10534P4MEDIUMCVSS 5.5fixed in binutils 2.30.90.20180627-1 (bookworm)2018
CVE-2018-10534 [MEDIUM] CVE-2018-10534: binutils - The _bfd_XX_bfd_copy_private_bfd_data_common function in peXXigen.c in the Binar... The _bfd_XX_bfd_copy_private_bfd_data_common function in peXXigen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, processes a negative Data Directory size with an unbounded loop that increases the value of (external_IMAGE_DEBUG_DIRECTORY) *edd so that the address exceeds its own memory region, resulting in an out-o
debian
CVE-2019-17450P4LOWCVSS 6.5fixed in binutils 2.34-1 (bookworm)2019
CVE-2019-17450 [MEDIUM] CVE-2019-17450: binutils - find_abstract_instance in dwarf2.c in the Binary File Descriptor (BFD) library (... find_abstract_instance in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32, allows remote attackers to cause a denial of service (infinite recursion and application crash) via a crafted ELF file. Scope: local bookworm: resolved (fixed in 2.34-1) bullseye: resolved (fixed in 2.34-1) forky: resolved (fixed in 2.
debian
Debian Binutils vulnerabilities | cvebase