VYPR

rpm package

opensuse/binutils&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/binutils&distro=openSUSE%20Tumbleweed

Vulnerabilities (156)

  • CVE-2020-16591Dec 9, 2020
    affected < 2.37-1.3fixed 2.37-1.3

    A Denial of Service vulnerability exists in the Binary File Descriptor (BFD) in GNU Binutils 2.35 due to an invalid read in process_symbol_table, as demonstrated in readeif.

  • CVE-2020-16590Dec 9, 2020
    affected < 2.37-1.3fixed 2.37-1.3

    A double free vulnerability exists in the Binary File Descriptor (BFD) (aka libbrd) in GNU Binutils 2.35 in the process_symbol_table, as demonstrated in readelf, via a crafted file.

  • CVE-2019-17450Oct 10, 2019
    affected < 2.37-1.3fixed 2.37-1.3

    find_abstract_instance in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32, allows remote attackers to cause a denial of service (infinite recursion and application crash) via a crafted ELF file.

  • CVE-2019-17451Oct 10, 2019
    affected < 2.37-1.3fixed 2.37-1.3

    An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is an integer overflow leading to a SEGV in _bfd_dwarf2_find_nearest_line in dwarf2.c, as demonstrated by nm.

  • CVE-2019-14444Jul 30, 2019
    affected < 2.37-1.3fixed 2.37-1.3

    apply_relocations in readelf.c in GNU Binutils 2.32 contains an integer overflow that allows attackers to trigger a write access violation (in byte_put_little_endian function in elfcomm.c) via an ELF file, as demonstrated by readelf.

  • CVE-2019-1010180Jul 24, 2019
    affected < 2.37-1.3fixed 2.37-1.3

    GNU gdb All versions is affected by: Buffer Overflow - Out of bound memory access. The impact is: Deny of Service, Memory Disclosure, and Possible Code Execution. The component is: The main gdb module. The attack vector is: Open an ELF for debugging. The fixed version is: Not fix

  • CVE-2019-14250Jul 24, 2019
    affected < 2.37-1.3fixed 2.37-1.3

    An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. simple_object_elf_match in simple-object-elf.c does not check for a zero shstrndx value, leading to an integer overflow and resultant heap-based buffer overflow.

  • CVE-2019-1010204Jul 23, 2019
    affected < 2.39-1.1fixed 2.39-1.1

    GNU binutils gold gold v1.11-v1.16 (GNU binutils v2.21-v2.31.1) is affected by: Improper Input Validation, Signed/Unsigned Comparison, Out-of-bounds Read. The impact is: Denial of service. The component is: gold/fileread.cc:497, elfcpp/elfcpp_file.h:644. The attack vector is: An

  • CVE-2019-12972Jun 26, 2019
    affected < 2.37-1.3fixed 2.37-1.3

    An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. There is a heap-based buffer over-read in _bfd_doprnt in bfd.c because elf_object_p in elfcode.h mishandles an e_shstrndx section of type SHT_GROUP by omitting a

  • CVE-2019-9077Feb 24, 2019
    affected < 2.37-1.3fixed 2.37-1.3

    An issue was discovered in GNU Binutils 2.32. It is a heap-based buffer overflow in process_mips_specific in readelf.c via a malformed MIPS option section.

  • CVE-2019-9075Feb 24, 2019
    affected < 2.37-1.3fixed 2.37-1.3

    An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is a heap-based buffer overflow in _bfd_archive_64_bit_slurp_armap in archive64.c.

  • CVE-2019-9074Feb 24, 2019
    affected < 2.37-1.3fixed 2.37-1.3

    An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is an out-of-bounds read leading to a SEGV in bfd_getl32 in libbfd.c, when called from pex64_get_runtime_function in pei-x86_64.c.

  • CVE-2018-20671Jan 4, 2019
    affected < 2.37-1.3fixed 2.37-1.3

    load_specific_debug_section in objdump.c in GNU Binutils through 2.31.1 contains an integer overflow vulnerability that can trigger a heap-based buffer overflow via a crafted section size.

  • CVE-2018-20651Jan 1, 2019
    affected < 2.37-1.3fixed 2.37-1.3

    A NULL pointer dereference was discovered in elf_link_add_object_symbols in elflink.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31.1. This occurs for a crafted ET_DYN with no program headers. A specially crafted ELF file allows rem

  • CVE-2018-20623Dec 31, 2018
    affected < 2.37-1.3fixed 2.37-1.3

    In GNU Binutils 2.31.1, there is a use-after-free in the error function in elfcomm.c when called from the process_archive function in readelf.c via a crafted ELF file.

  • CVE-2018-1000876Dec 20, 2018
    affected < 2.37-1.3fixed 2.37-1.3

    binutils version 2.32 and earlier contains a Integer Overflow vulnerability in objdump, bfd_get_dynamic_reloc_upper_bound,bfd_canonicalize_dynamic_reloc that can result in Integer overflow trigger heap overflow. Successful exploitation allows execution of arbitrary code.. This at

  • CVE-2018-19932Dec 7, 2018
    affected < 2.37-1.3fixed 2.37-1.3

    An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils through 2.31. There is an integer overflow and infinite loop caused by the IS_CONTAINED_BY_LMA macro in elf.c.

  • CVE-2018-19931Dec 7, 2018
    affected < 2.37-1.3fixed 2.37-1.3

    An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils through 2.31. There is a heap-based buffer overflow in bfd_elf32_swap_phdr_in in elfcode.h because the number of program headers is not restricted.

  • CVE-2018-18607Oct 23, 2018
    affected < 2.37-1.3fixed 2.37-1.3

    An issue was discovered in elf_link_input_bfd in elflink.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. There is a NULL pointer dereference in elf_link_input_bfd when used for finding STT_TLS symbols without any TLS section. A spe

  • CVE-2018-18606Oct 23, 2018
    affected < 2.37-1.3fixed 2.37-1.3

    An issue was discovered in the merge_strings function in merge.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. There is a NULL pointer dereference in _bfd_add_merge_section when attempting to merge sections with large alignments. A

Page 4 of 8