rpm package
suse/binutils&distro=SUSE Linux Enterprise Server 12 SP2-LTSS
pkg:rpm/suse/binutils&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-LTSS
Vulnerabilities (69)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2019-1010180 | — | < 2.32-9.33.1 | 2.32-9.33.1 | Jul 24, 2019 | GNU gdb All versions is affected by: Buffer Overflow - Out of bound memory access. The impact is: Deny of Service, Memory Disclosure, and Possible Code Execution. The component is: The main gdb module. The attack vector is: Open an ELF for debugging. The fixed version is: Not fix | ||
| CVE-2018-20671 | — | < 2.32-9.33.1 | 2.32-9.33.1 | Jan 4, 2019 | load_specific_debug_section in objdump.c in GNU Binutils through 2.31.1 contains an integer overflow vulnerability that can trigger a heap-based buffer overflow via a crafted section size. | ||
| CVE-2018-20651 | — | < 2.32-9.33.1 | 2.32-9.33.1 | Jan 1, 2019 | A NULL pointer dereference was discovered in elf_link_add_object_symbols in elflink.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31.1. This occurs for a crafted ET_DYN with no program headers. A specially crafted ELF file allows rem | ||
| CVE-2018-20623 | — | < 2.32-9.33.1 | 2.32-9.33.1 | Dec 31, 2018 | In GNU Binutils 2.31.1, there is a use-after-free in the error function in elfcomm.c when called from the process_archive function in readelf.c via a crafted ELF file. | ||
| CVE-2018-1000876 | — | < 2.32-9.33.1 | 2.32-9.33.1 | Dec 20, 2018 | binutils version 2.32 and earlier contains a Integer Overflow vulnerability in objdump, bfd_get_dynamic_reloc_upper_bound,bfd_canonicalize_dynamic_reloc that can result in Integer overflow trigger heap overflow. Successful exploitation allows execution of arbitrary code.. This at | ||
| CVE-2018-19932 | — | < 2.32-9.33.1 | 2.32-9.33.1 | Dec 7, 2018 | An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils through 2.31. There is an integer overflow and infinite loop caused by the IS_CONTAINED_BY_LMA macro in elf.c. | ||
| CVE-2018-19931 | — | < 2.32-9.33.1 | 2.32-9.33.1 | Dec 7, 2018 | An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils through 2.31. There is a heap-based buffer overflow in bfd_elf32_swap_phdr_in in elfcode.h because the number of program headers is not restricted. | ||
| CVE-2018-18607 | — | < 2.32-9.33.1 | 2.32-9.33.1 | Oct 23, 2018 | An issue was discovered in elf_link_input_bfd in elflink.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. There is a NULL pointer dereference in elf_link_input_bfd when used for finding STT_TLS symbols without any TLS section. A spe | ||
| CVE-2018-18606 | — | < 2.32-9.33.1 | 2.32-9.33.1 | Oct 23, 2018 | An issue was discovered in the merge_strings function in merge.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. There is a NULL pointer dereference in _bfd_add_merge_section when attempting to merge sections with large alignments. A | ||
| CVE-2018-18605 | — | < 2.32-9.33.1 | 2.32-9.33.1 | Oct 23, 2018 | A heap-based buffer over-read issue was discovered in the function sec_merge_hash_lookup in merge.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31, because _bfd_add_merge_section mishandles section merges when size is not a multiple | ||
| CVE-2018-18484 | — | < 2.32-9.33.1 | 2.32-9.33.1 | Oct 18, 2018 | An issue was discovered in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31. Stack Exhaustion occurs in the C++ demangling functions provided by libiberty, and there is a stack consumption problem caused by recursive stack frames: cplus_demangle_type, d_bare_fu | ||
| CVE-2018-18483 | — | < 2.32-9.33.1 | 2.32-9.33.1 | Oct 18, 2018 | The get_count function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31, allows remote attackers to cause a denial of service (malloc called with the result of an integer-overflowing calculation) or possibly have unspecified other impact via a crafted string, | ||
| CVE-2018-18309 | — | < 2.32-9.33.1 | 2.32-9.33.1 | Oct 15, 2018 | An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. An invalid memory address dereference was discovered in read_reloc in reloc.c. The vulnerability causes a segmentation fault and application crash, which leads t | ||
| CVE-2018-17985 | — | < 2.32-9.33.1 | 2.32-9.33.1 | Oct 4, 2018 | An issue was discovered in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31. There is a stack consumption problem caused by the cplus_demangle_type function making recursive calls to itself in certain scenarios involving many 'P' characters. | ||
| CVE-2018-17360 | — | < 2.32-9.33.1 | 2.32-9.33.1 | Sep 23, 2018 | An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. a heap-based buffer over-read in bfd_getl32 in libbfd.c allows an attacker to cause a denial of service through a crafted PE file. This vulnerability can be trig | ||
| CVE-2018-17359 | — | < 2.32-9.33.1 | 2.32-9.33.1 | Sep 23, 2018 | An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. An invalid memory access exists in bfd_zalloc in opncls.c. Attackers could leverage this vulnerability to cause a denial of service (application crash) via a cra | ||
| CVE-2018-17358 | — | < 2.32-9.33.1 | 2.32-9.33.1 | Sep 23, 2018 | An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. An invalid memory access exists in _bfd_stab_section_find_nearest_line in syms.c. Attackers could leverage this vulnerability to cause a denial of service (appli | ||
| CVE-2018-10535 | — | < 2.31-9.26.1 | 2.31-9.26.1 | Apr 29, 2018 | The ignore_section_sym function in elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, does not validate the output_section pointer in the case of a symtab entry with a "SECTION" type that has a "0" value, which allows remote attac | ||
| CVE-2018-10534 | — | < 2.31-9.26.1 | 2.31-9.26.1 | Apr 29, 2018 | The _bfd_XX_bfd_copy_private_bfd_data_common function in peXXigen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, processes a negative Data Directory size with an unbounded loop that increases the value of (external_IMAGE_DEBUG_DIR | ||
| CVE-2018-10373 | — | < 2.31-9.26.1 | 2.31-9.26.1 | Apr 25, 2018 | concat_filename in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted binary file, as demonstrated by nm-new. |
- CVE-2019-1010180Jul 24, 2019affected < 2.32-9.33.1fixed 2.32-9.33.1
GNU gdb All versions is affected by: Buffer Overflow - Out of bound memory access. The impact is: Deny of Service, Memory Disclosure, and Possible Code Execution. The component is: The main gdb module. The attack vector is: Open an ELF for debugging. The fixed version is: Not fix
- CVE-2018-20671Jan 4, 2019affected < 2.32-9.33.1fixed 2.32-9.33.1
load_specific_debug_section in objdump.c in GNU Binutils through 2.31.1 contains an integer overflow vulnerability that can trigger a heap-based buffer overflow via a crafted section size.
- CVE-2018-20651Jan 1, 2019affected < 2.32-9.33.1fixed 2.32-9.33.1
A NULL pointer dereference was discovered in elf_link_add_object_symbols in elflink.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31.1. This occurs for a crafted ET_DYN with no program headers. A specially crafted ELF file allows rem
- CVE-2018-20623Dec 31, 2018affected < 2.32-9.33.1fixed 2.32-9.33.1
In GNU Binutils 2.31.1, there is a use-after-free in the error function in elfcomm.c when called from the process_archive function in readelf.c via a crafted ELF file.
- CVE-2018-1000876Dec 20, 2018affected < 2.32-9.33.1fixed 2.32-9.33.1
binutils version 2.32 and earlier contains a Integer Overflow vulnerability in objdump, bfd_get_dynamic_reloc_upper_bound,bfd_canonicalize_dynamic_reloc that can result in Integer overflow trigger heap overflow. Successful exploitation allows execution of arbitrary code.. This at
- CVE-2018-19932Dec 7, 2018affected < 2.32-9.33.1fixed 2.32-9.33.1
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils through 2.31. There is an integer overflow and infinite loop caused by the IS_CONTAINED_BY_LMA macro in elf.c.
- CVE-2018-19931Dec 7, 2018affected < 2.32-9.33.1fixed 2.32-9.33.1
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils through 2.31. There is a heap-based buffer overflow in bfd_elf32_swap_phdr_in in elfcode.h because the number of program headers is not restricted.
- CVE-2018-18607Oct 23, 2018affected < 2.32-9.33.1fixed 2.32-9.33.1
An issue was discovered in elf_link_input_bfd in elflink.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. There is a NULL pointer dereference in elf_link_input_bfd when used for finding STT_TLS symbols without any TLS section. A spe
- CVE-2018-18606Oct 23, 2018affected < 2.32-9.33.1fixed 2.32-9.33.1
An issue was discovered in the merge_strings function in merge.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. There is a NULL pointer dereference in _bfd_add_merge_section when attempting to merge sections with large alignments. A
- CVE-2018-18605Oct 23, 2018affected < 2.32-9.33.1fixed 2.32-9.33.1
A heap-based buffer over-read issue was discovered in the function sec_merge_hash_lookup in merge.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31, because _bfd_add_merge_section mishandles section merges when size is not a multiple
- CVE-2018-18484Oct 18, 2018affected < 2.32-9.33.1fixed 2.32-9.33.1
An issue was discovered in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31. Stack Exhaustion occurs in the C++ demangling functions provided by libiberty, and there is a stack consumption problem caused by recursive stack frames: cplus_demangle_type, d_bare_fu
- CVE-2018-18483Oct 18, 2018affected < 2.32-9.33.1fixed 2.32-9.33.1
The get_count function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31, allows remote attackers to cause a denial of service (malloc called with the result of an integer-overflowing calculation) or possibly have unspecified other impact via a crafted string,
- CVE-2018-18309Oct 15, 2018affected < 2.32-9.33.1fixed 2.32-9.33.1
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. An invalid memory address dereference was discovered in read_reloc in reloc.c. The vulnerability causes a segmentation fault and application crash, which leads t
- CVE-2018-17985Oct 4, 2018affected < 2.32-9.33.1fixed 2.32-9.33.1
An issue was discovered in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31. There is a stack consumption problem caused by the cplus_demangle_type function making recursive calls to itself in certain scenarios involving many 'P' characters.
- CVE-2018-17360Sep 23, 2018affected < 2.32-9.33.1fixed 2.32-9.33.1
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. a heap-based buffer over-read in bfd_getl32 in libbfd.c allows an attacker to cause a denial of service through a crafted PE file. This vulnerability can be trig
- CVE-2018-17359Sep 23, 2018affected < 2.32-9.33.1fixed 2.32-9.33.1
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. An invalid memory access exists in bfd_zalloc in opncls.c. Attackers could leverage this vulnerability to cause a denial of service (application crash) via a cra
- CVE-2018-17358Sep 23, 2018affected < 2.32-9.33.1fixed 2.32-9.33.1
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. An invalid memory access exists in _bfd_stab_section_find_nearest_line in syms.c. Attackers could leverage this vulnerability to cause a denial of service (appli
- CVE-2018-10535Apr 29, 2018affected < 2.31-9.26.1fixed 2.31-9.26.1
The ignore_section_sym function in elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, does not validate the output_section pointer in the case of a symtab entry with a "SECTION" type that has a "0" value, which allows remote attac
- CVE-2018-10534Apr 29, 2018affected < 2.31-9.26.1fixed 2.31-9.26.1
The _bfd_XX_bfd_copy_private_bfd_data_common function in peXXigen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, processes a negative Data Directory size with an unbounded loop that increases the value of (external_IMAGE_DEBUG_DIR
- CVE-2018-10373Apr 25, 2018affected < 2.31-9.26.1fixed 2.31-9.26.1
concat_filename in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted binary file, as demonstrated by nm-new.
Page 1 of 4