Debian Binutils vulnerabilities
259 known vulnerabilities affecting debian/binutils.
Total CVEs
259
CISA KEV
0
Public exploits
12
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH40MEDIUM23LOW193
Vulnerabilities
Page 9 of 13
CVE-2018-20623P4LOWCVSS 5.5fixed in binutils 2.32.51.20190707-1 (bookworm)2018
CVE-2018-20623 [MEDIUM] CVE-2018-20623: binutils - In GNU Binutils 2.31.1, there is a use-after-free in the error function in elfco...
In GNU Binutils 2.31.1, there is a use-after-free in the error function in elfcomm.c when called from the process_archive function in readelf.c via a crafted ELF file.
Scope: local
bookworm: resolved (fixed in 2.32.51.20190707-1)
bullseye: resolved (fixed in 2.32.51.20190707-1)
forky: resolved (fixed in 2.32.51.20190707-1)
sid: resolved (fixed in 2.32.51.20190707
debian
CVE-2019-9071P4LOWCVSS 5.5fixed in binutils 2.32.51.20190707-1 (bookworm)2019
CVE-2019-9071 [MEDIUM] CVE-2019-9071: binutils - An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. I...
An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. It is a stack consumption issue in d_count_templates_scopes in cp-demangle.c after many recursive calls.
Scope: local
bookworm: resolved (fixed in 2.32.51.20190707-1)
bullseye: resolved (fixed in 2.32.51.20190707-1)
forky: resolved (fixed in 2.32.51.20190707-1)
sid: resolved (fixed in 2.
debian
CVE-2016-4488P4LOWCVSS 5.5fixed in binutils 2.27.51.20161102-1 (bookworm)2016
CVE-2016-4488 [MEDIUM] CVE-2016-4488: binutils - Use-after-free vulnerability in libiberty allows remote attackers to cause a den...
Use-after-free vulnerability in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary, related to "ktypevec."
Scope: local
bookworm: resolved (fixed in 2.27.51.20161102-1)
bullseye: resolved (fixed in 2.27.51.20161102-1)
forky: resolved (fixed in 2.27.51.20161102-1)
sid: resolved (fixed in 2.27.51.2016110
debian
CVE-2016-4487P4LOWCVSS 5.5fixed in binutils 2.27.51.20161102-1 (bookworm)2016
CVE-2016-4487 [MEDIUM] CVE-2016-4487: binutils - Use-after-free vulnerability in libiberty allows remote attackers to cause a den...
Use-after-free vulnerability in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary, related to "btypevec."
Scope: local
bookworm: resolved (fixed in 2.27.51.20161102-1)
bullseye: resolved (fixed in 2.27.51.20161102-1)
forky: resolved (fixed in 2.27.51.20161102-1)
sid: resolved (fixed in 2.27.51.2016110
debian
CVE-2019-9074P4LOWCVSS 5.5fixed in binutils 2.32.51.20190707-1 (bookworm)2019
CVE-2019-9074 [MEDIUM] CVE-2019-9074: binutils - An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd)...
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is an out-of-bounds read leading to a SEGV in bfd_getl32 in libbfd.c, when called from pex64_get_runtime_function in pei-x86_64.c.
Scope: local
bookworm: resolved (fixed in 2.32.51.20190707-1)
bullseye: resolved (fixed in 2.32.51.20190707-1)
for
debian
CVE-2021-20284P4LOWCVSS 5.5fixed in binutils 2.37-3 (bookworm)2021
CVE-2021-20284 [MEDIUM] CVE-2021-20284: binutils - A flaw was found in GNU Binutils 2.35.1, where there is a heap-based buffer over...
A flaw was found in GNU Binutils 2.35.1, where there is a heap-based buffer overflow in _bfd_elf_slurp_secondary_reloc_section in elf.c due to the number of symbols not calculated correctly. The highest threat from this vulnerability is to system availability.
Scope: local
bookworm: resolved (fixed in 2.37-3)
bullseye: open
forky: resolved (fixed in 2.37-3)
sid:
debian
CVE-2020-35507P4LOWCVSS 5.5fixed in binutils 2.33.50.20200107-1 (bookworm)2020
CVE-2020-35507 [MEDIUM] CVE-2020-35507: binutils - There's a flaw in bfd_pef_parse_function_stubs of bfd/pef.c in binutils in versi...
There's a flaw in bfd_pef_parse_function_stubs of bfd/pef.c in binutils in versions prior to 2.34 which could allow an attacker who is able to submit a crafted file to be processed by objdump to cause a NULL pointer dereference. The greatest threat of this flaw is to application availability.
Scope: local
bookworm: resolved (fixed in 2.33.50.20200107-1)
bullseye:
debian
CVE-2020-35495P4LOWCVSS 5.5fixed in binutils 2.33.50.20200107-1 (bookworm)2020
CVE-2020-35495 [MEDIUM] CVE-2020-35495: binutils - There's a flaw in binutils /bfd/pef.c. An attacker who is able to submit a craft...
There's a flaw in binutils /bfd/pef.c. An attacker who is able to submit a crafted input file to be processed by the objdump program could cause a null pointer dereference. The greatest threat from this flaw is to application availability. This flaw affects binutils versions prior to 2.34.
Scope: local
bookworm: resolved (fixed in 2.33.50.20200107-1)
bullseye: re
debian
CVE-2020-35496P4LOWCVSS 5.5fixed in binutils 2.33.50.20200107-1 (bookworm)2020
CVE-2020-35496 [MEDIUM] CVE-2020-35496: binutils - There's a flaw in bfd_pef_scan_start_address() of bfd/pef.c in binutils which co...
There's a flaw in bfd_pef_scan_start_address() of bfd/pef.c in binutils which could allow an attacker who is able to submit a crafted file to be processed by objdump to cause a NULL pointer dereference. The greatest threat of this flaw is to application availability. This flaw affects binutils versions prior to 2.34.
Scope: local
bookworm: resolved (fixed in 2.33
debian
CVE-2018-13033P4LOWCVSS 5.5fixed in binutils 2.30.90.20180627-1 (bookworm)2018
CVE-2018-13033 [MEDIUM] CVE-2018-13033: binutils - The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Bin...
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted ELF file, as demonstrated by _bfd_elf_parse_attributes in elf-attrs.c and bfd_malloc in libbfd.c. This can occur during execution of nm.
Scope: local
book
debian
CVE-2018-10372P4MEDIUMCVSS 5.5fixed in binutils 2.30.90.20180627-1 (bookworm)2018
CVE-2018-10372 [MEDIUM] CVE-2018-10372: binutils - process_cu_tu_index in dwarf.c in GNU Binutils 2.30 allows remote attackers to c...
process_cu_tu_index in dwarf.c in GNU Binutils 2.30 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted binary file, as demonstrated by readelf.
Scope: local
bookworm: resolved (fixed in 2.30.90.20180627-1)
bullseye: resolved (fixed in 2.30.90.20180627-1)
forky: resolved (fixed in 2.30.90.20180627
debian
CVE-2018-6872P4MEDIUMCVSS 5.5fixed in binutils 2.30-4 (bookworm)2018
CVE-2018-6872 [MEDIUM] CVE-2018-6872: binutils - The elf_parse_notes function in elf.c in the Binary File Descriptor (BFD) librar...
The elf_parse_notes function in elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to cause a denial of service (out-of-bounds read and segmentation violation) via a note with a large alignment.
Scope: local
bookworm: resolved (fixed in 2.30-4)
bullseye: resolved (fixed in 2.30-4)
forky: reso
debian
CVE-2017-9038P4LOWCVSS 5.5fixed in binutils 2.28-6 (bookworm)2017
CVE-2017-9038 [MEDIUM] CVE-2017-9038: binutils - GNU Binutils 2.28 allows remote attackers to cause a denial of service (heap-bas...
GNU Binutils 2.28 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file, related to the byte_get_little_endian function in elfcomm.c, the get_unwind_section_word function in readelf.c, and ARM unwind information that contains invalid word offsets.
Scope: local
bookworm: resolved (fixed in 2.2
debian
CVE-2017-9040P4LOWCVSS 5.5fixed in binutils 2.29-1 (bookworm)2017
CVE-2017-9040 [MEDIUM] CVE-2017-9040: binutils - GNU Binutils 2017-04-03 allows remote attackers to cause a denial of service (NU...
GNU Binutils 2017-04-03 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash), related to the process_mips_specific function in readelf.c, via a crafted ELF file that triggers a large memory-allocation attempt.
Scope: local
bookworm: resolved (fixed in 2.29-1)
bullseye: resolved (fixed in 2.29-1)
forky: resolved (fixe
debian
CVE-2017-15022P4LOWCVSS 5.5fixed in binutils 2.29.90.20180122-1 (bookworm)2017
CVE-2017-15022 [MEDIUM] CVE-2017-15022: binutils - dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distribute...
dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, does not validate the DW_AT_name data type, which allows remote attackers to cause a denial of service (bfd_hash_hash NULL pointer dereference, or out-of-bounds access, and application crash) via a crafted ELF file, related to scan_unit_for_symbols and parse_co
debian
CVE-2017-9041P4LOWCVSS 5.5fixed in binutils 2.28-6 (bookworm)2017
CVE-2017-9041 [MEDIUM] CVE-2017-9041: binutils - GNU Binutils 2.28 allows remote attackers to cause a denial of service (heap-bas...
GNU Binutils 2.28 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file, related to MIPS GOT mishandling in the process_mips_specific function in readelf.c.
Scope: local
bookworm: resolved (fixed in 2.28-6)
bullseye: resolved (fixed in 2.28-6)
forky: resolved (fixed in 2.28-6)
sid: resolved (
debian
CVE-2016-4489P4LOWCVSS 5.5fixed in binutils 2.27.51.20161102-1 (bookworm)2016
CVE-2016-4489 [MEDIUM] CVE-2016-4489: binutils - Integer overflow in the gnu_special function in libiberty allows remote attacker...
Integer overflow in the gnu_special function in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary, related to the "demangling of virtual tables."
Scope: local
bookworm: resolved (fixed in 2.27.51.20161102-1)
bullseye: resolved (fixed in 2.27.51.20161102-1)
forky: resolved (fixed in 2.27.51.20161102-1)
debian
CVE-2018-18700P4LOWCVSS 5.5fixed in binutils 2.32.51.20190707-1 (bookworm)2018
CVE-2018-18700 [MEDIUM] CVE-2018-18700: binutils - An issue was discovered in cp-demangle.c in GNU libiberty, as distributed in GNU...
An issue was discovered in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31. There is a stack consumption vulnerability resulting from infinite recursion in the functions d_name(), d_encoding(), and d_local_name() in cp-demangle.c. Remote attackers could leverage this vulnerability to cause a denial-of-service via an ELF file, as demonstrated b
debian
CVE-2018-18701P4LOWCVSS 5.5fixed in binutils 2.32.51.20190707-1 (bookworm)2018
CVE-2018-18701 [MEDIUM] CVE-2018-18701: binutils - An issue was discovered in cp-demangle.c in GNU libiberty, as distributed in GNU...
An issue was discovered in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31. There is a stack consumption vulnerability resulting from infinite recursion in the functions next_is_type_qual() and cplus_demangle_type() in cp-demangle.c. Remote attackers could leverage this vulnerability to cause a denial-of-service via an ELF file, as demonstrate
debian
CVE-2017-9954P4MEDIUMCVSS 5.5fixed in binutils 2.29-1 (bookworm)2017
CVE-2017-9954 [MEDIUM] CVE-2017-9954: binutils - The getvalue function in tekhex.c in the Binary File Descriptor (BFD) library (a...
The getvalue function in tekhex.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a crafted tekhex file, as demonstrated by mishandling within the nm program.
Scope: local
bookworm: resolved (fixed in 2.29-1)
b
debian