Gnu Binutils vulnerabilities

285 known vulnerabilities affecting gnu/binutils.

Total CVEs
285
CISA KEV
0
Public exploits
12
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH112MEDIUM153LOW15

Vulnerabilities

Page 5 of 15
CVE-2021-3530HIGHCVSS 7.5v2.36vGNU Binutils version before and including 2.362021-06-02
CVE-2021-3530 [HIGH] CWE-674 CVE-2021-3530: A flaw was discovered in GNU libiberty within demangle_path() in rust-demangle.c, as distributed in A flaw was discovered in GNU libiberty within demangle_path() in rust-demangle.c, as distributed in GNU Binutils version 2.36. A crafted symbol can cause stack memory to be exhausted leading to a crash.
cvelistv5nvdosv
CVE-2021-3549HIGHCVSS 7.1v2.36vGNU binutils version 2.362021-05-26
CVE-2021-3549 [HIGH] CWE-119 CVE-2021-3549: An out of bounds flaw was found in GNU binutils objdump utility version 2.36. An attacker could use An out of bounds flaw was found in GNU binutils objdump utility version 2.36. An attacker could use this flaw and pass a large section to avr_elf32_load_records_from_section() probably resulting in a crash or in some cases memory corruption. The highest threat from this vulnerability is to integrity as well as system availability.
cvelistv5nvdosv
CVE-2021-20294HIGHCVSS 7.8≥ 2.35, < 2.35.2vbinutils 2.35.22021-04-29
CVE-2021-20294 [HIGH] CWE-787 CVE-2021-20294: A flaw was found in binutils readelf 2.35 program. An attacker who is able to convince a victim usin A flaw was found in binutils readelf 2.35 program. An attacker who is able to convince a victim using readelf to read a crafted file could trigger a stack buffer overflow, out-of-bounds write of arbitrary data supplied by the attacker. The highest impact of this flaw is to confidentiality, integrity, and availability.
cvelistv5nvdosv
CVE-2021-20197MEDIUMCVSS 6.3≤ 2.35vbinutils 2.352021-03-26
CVE-2021-20197 [MEDIUM] CWE-59 CVE-2021-20197: There is an open race window when writing output in the following utilities in GNU binutils version There is an open race window when writing output in the following utilities in GNU binutils version 2.35 and earlier:ar, objcopy, strip, ranlib. When these utilities are run as a privileged user (presumably as part of a script updating binaries across different users), an unprivileged user can trick these utilities into getting ownership of arbitrary
cvelistv5nvdosv
CVE-2021-20284MEDIUMCVSS 5.5v2.35.1vBinutils 2.35.12021-03-26
CVE-2021-20284 [MEDIUM] CWE-119 CVE-2021-20284: A flaw was found in GNU Binutils 2.35.1, where there is a heap-based buffer overflow in _bfd_elf_slu A flaw was found in GNU Binutils 2.35.1, where there is a heap-based buffer overflow in _bfd_elf_slurp_secondary_reloc_section in elf.c due to the number of symbols not calculated correctly. The highest threat from this vulnerability is to system availability.
cvelistv5nvdosv
CVE-2020-35496MEDIUMCVSS 5.5fixed in 2.34vbinutils 2.342021-01-04
CVE-2020-35496 [MEDIUM] CWE-476 CVE-2020-35496: There's a flaw in bfd_pef_scan_start_address() of bfd/pef.c in binutils which could allow an attacke There's a flaw in bfd_pef_scan_start_address() of bfd/pef.c in binutils which could allow an attacker who is able to submit a crafted file to be processed by objdump to cause a NULL pointer dereference. The greatest threat of this flaw is to application availability. This flaw affects binutils versions prior to 2.34.
cvelistv5nvdosv
CVE-2020-35507MEDIUMCVSS 5.5fixed in 2.34vbinutils 2.342021-01-04
CVE-2020-35507 [MEDIUM] CWE-476 CVE-2020-35507: There's a flaw in bfd_pef_parse_function_stubs of bfd/pef.c in binutils in versions prior to 2.34 wh There's a flaw in bfd_pef_parse_function_stubs of bfd/pef.c in binutils in versions prior to 2.34 which could allow an attacker who is able to submit a crafted file to be processed by objdump to cause a NULL pointer dereference. The greatest threat of this flaw is to application availability.
cvelistv5nvdosv
CVE-2020-35493MEDIUMCVSS 5.5fixed in 2.34vbinutils 2.342021-01-04
CVE-2020-35493 [MEDIUM] CWE-20 CVE-2020-35493: A flaw exists in binutils in bfd/pef.c. An attacker who is able to submit a crafted PEF file to be p A flaw exists in binutils in bfd/pef.c. An attacker who is able to submit a crafted PEF file to be parsed by objdump could cause a heap buffer overflow -> out-of-bounds read that could lead to an impact to application availability. This flaw affects binutils versions prior to 2.34.
cvelistv5nvdosv
CVE-2020-35495MEDIUMCVSS 5.5fixed in 2.34vbinutils 2.342021-01-04
CVE-2020-35495 [MEDIUM] CWE-476 CVE-2020-35495: There's a flaw in binutils /bfd/pef.c. An attacker who is able to submit a crafted input file to be There's a flaw in binutils /bfd/pef.c. An attacker who is able to submit a crafted input file to be processed by the objdump program could cause a null pointer dereference. The greatest threat from this flaw is to application availability. This flaw affects binutils versions prior to 2.34.
cvelistv5nvdosv
CVE-2020-35494MEDIUMCVSS 6.1fixed in 2.34vbinutils 2.342021-01-04
CVE-2020-35494 [MEDIUM] CWE-908 CVE-2020-35494: There's a flaw in binutils /opcodes/tic4x-dis.c. An attacker who is able to submit a crafted input f There's a flaw in binutils /opcodes/tic4x-dis.c. An attacker who is able to submit a crafted input file to be processed by binutils could cause usage of uninitialized memory. The highest threat is to application availability with a lower threat to data confidentiality. This flaw affects binutils versions prior to 2.34.
cvelistv5nvdosv
CVE-2020-35448LOWCVSS 3.3v2.35.12020-12-27
CVE-2020-35448 [LOW] CWE-125 CVE-2020-35448: An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.35.1. A heap-based buffer over-read can occur in bfd_getl_signed_32 in libbfd.c because sh_entsize is not validated in _bfd_elf_slurp_secondary_reloc_section in elf.c.
nvdosv
CVE-2020-16593MEDIUMCVSS 5.5v2.352020-12-09
CVE-2020-16593 [MEDIUM] CWE-476 CVE-2020-16593: A Null Pointer Dereference vulnerability exists in the Binary File Descriptor (BFD) library (aka lib A Null Pointer Dereference vulnerability exists in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.35, in scan_unit_for_symbols, as demonstrated in addr2line, that can cause a denial of service via a crafted file.
nvdosv
CVE-2020-16599MEDIUMCVSS 5.5v2.35vbinutils 2.39-72020-12-09
CVE-2020-16599 [MEDIUM] CWE-476 CVE-2020-16599: A Null Pointer Dereference vulnerability exists in the Binary File Descriptor (BFD) library (aka lib A Null Pointer Dereference vulnerability exists in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.35, in _bfd_elf_get_symbol_version_string, as demonstrated in nm-new, that can cause a denial of service via a crafted file.
nvdosv
CVE-2020-16592MEDIUMCVSS 5.5v2.342020-12-09
CVE-2020-16592 [MEDIUM] CWE-416 CVE-2020-16592: A use after free issue exists in the Binary File Descriptor (BFD) library (aka libbfd) in GNU Binuti A use after free issue exists in the Binary File Descriptor (BFD) library (aka libbfd) in GNU Binutils 2.34 in bfd_hash_lookup, as demonstrated in nm-new, that can cause a denial of service via a crafted file.
nvdosv
CVE-2020-16591MEDIUMCVSS 5.5v2.352020-12-09
CVE-2020-16591 [MEDIUM] CWE-125 CVE-2020-16591: A Denial of Service vulnerability exists in the Binary File Descriptor (BFD) in GNU Binutils 2.35 du A Denial of Service vulnerability exists in the Binary File Descriptor (BFD) in GNU Binutils 2.35 due to an invalid read in process_symbol_table, as demonstrated in readeif.
nvdosv
CVE-2020-16590MEDIUMCVSS 5.5v2.352020-12-09
CVE-2020-16590 [MEDIUM] CWE-415 CVE-2020-16590: A double free vulnerability exists in the Binary File Descriptor (BFD) (aka libbrd) in GNU Binutils A double free vulnerability exists in the Binary File Descriptor (BFD) (aka libbrd) in GNU Binutils 2.35 in the process_symbol_table, as demonstrated in readelf, via a crafted file.
nvdosv
CVE-2019-17450MEDIUMCVSS 6.5v2.322019-10-10
CVE-2019-17450 [MEDIUM] CWE-674 CVE-2019-17450: find_abstract_instance in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as dist find_abstract_instance in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32, allows remote attackers to cause a denial of service (infinite recursion and application crash) via a crafted ELF file.
nvdosv
CVE-2019-17451MEDIUMCVSS 6.5v2.322019-10-10
CVE-2019-17451 [MEDIUM] CWE-190 CVE-2019-17451: An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is an integer overflow leading to a SEGV in _bfd_dwarf2_find_nearest_line in dwarf2.c, as demonstrated by nm.
nvdosv
CVE-2019-14444MEDIUMCVSS 5.5v2.322019-07-30
CVE-2019-14444 [MEDIUM] CWE-190 CVE-2019-14444: apply_relocations in readelf.c in GNU Binutils 2.32 contains an integer overflow that allows attacke apply_relocations in readelf.c in GNU Binutils 2.32 contains an integer overflow that allows attackers to trigger a write access violation (in byte_put_little_endian function in elfcomm.c) via an ELF file, as demonstrated by readelf.
nvdosv
CVE-2019-1010180HIGHCVSS 7.8≥ 0, < 2.32.51.20190707-12019-07-24
CVE-2019-1010180 [HIGH] CVE-2019-1010180: GNU gdb All versions is affected by: Buffer Overflow - Out of bound memory access GNU gdb All versions is affected by: Buffer Overflow - Out of bound memory access. The impact is: Deny of Service, Memory Disclosure, and Possible Code Execution. The component is: The main gdb module. The attack vector is: Open an ELF for debugging. The fixed version is: Not fixed yet.
osv