This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Gnu First view 2014-12-09
Product Binutils Last view 2019-07-23
Version 2.23.2 Type Application
Update *  
Edition *  
Language *  
Sofware Edition *  
Target Software *  
Target Hardware *  
Other *  
 
CPE Product cpe:2.3:a:gnu:binutils

Activity : Overall

Related : CVE

This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
  Date Alert Description
5.5 2019-07-23 CVE-2019-1010204

GNU binutils gold gold v1.11-v1.16 (GNU binutils v2.21-v2.31.1) is affected by: Improper Input Validation, Signed/Unsigned Comparison, Out-of-bounds Read. The impact is: Denial of service. The component is: gold/fileread.cc:497, elfcpp/elfcpp_file.h:644. The attack vector is: An ELF file with an invalid e_shoff header field must be opened.

5.5 2019-01-04 CVE-2018-20671

load_specific_debug_section in objdump.c in GNU Binutils through 2.31.1 contains an integer overflow vulnerability that can trigger a heap-based buffer overflow via a crafted section size.

7.8 2018-12-20 CVE-2018-1000876

binutils version 2.32 and earlier contains a Integer Overflow vulnerability in objdump, bfd_get_dynamic_reloc_upper_bound,bfd_canonicalize_dynamic_reloc that can result in Integer overflow trigger heap overflow. Successful exploitation allows execution of arbitrary code.. This attack appear to be exploitable via Local. This vulnerability appears to have been fixed in after commit 3a551c7a1b80fca579461774860574eabfd7f18f.

5.5 2018-12-07 CVE-2018-19932

An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils through 2.31. There is an integer overflow and infinite loop caused by the IS_CONTAINED_BY_LMA macro in elf.c.

7.8 2018-12-07 CVE-2018-19931

An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils through 2.31. There is a heap-based buffer overflow in bfd_elf32_swap_phdr_in in elfcode.h because the number of program headers is not restricted.

7.8 2017-08-04 CVE-2017-12459

The bfd_mach_o_read_symtab_strtab function in bfd/mach-o.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an out of bounds heap write and possibly achieve code execution via a crafted mach-o file.

7.8 2017-08-04 CVE-2017-12458

The nlm_swap_auxiliary_headers_in function in bfd/nlmcode.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an out of bounds heap read via a crafted nlm file.

7.8 2017-08-04 CVE-2017-12457

The bfd_make_section_with_flags function in section.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause a NULL dereference via a crafted file.

7.8 2017-08-04 CVE-2017-12456

The read_symbol_stabs_debugging_info function in rddbg.c in GNU Binutils 2.29 and earlier allows remote attackers to cause an out of bounds heap read via a crafted binary file.

7.8 2017-08-04 CVE-2017-12455

The evax_bfd_print_emh function in vms-alpha.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an out of bounds heap read via a crafted vms alpha file.

7.8 2017-08-04 CVE-2017-12454

The _bfd_vms_slurp_egsd function in bfd/vms-alpha.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an arbitrary memory read via a crafted vms alpha file.

7.8 2017-08-04 CVE-2017-12453

The _bfd_vms_slurp_eeom function in libbfd.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an out of bounds heap read via a crafted vms alpha file.

7.8 2017-08-04 CVE-2017-12452

The bfd_mach_o_i386_canonicalize_one_reloc function in bfd/mach-o-i386.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an out of bounds heap read via a crafted mach-o file.

7.8 2017-08-04 CVE-2017-12451

The _bfd_xcoff_read_ar_hdr function in bfd/coff-rs6000.c and bfd/coff64-rs6000.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an out of bounds stack read via a crafted COFF image file.

7.8 2017-08-04 CVE-2017-12450

The alpha_vms_object_p function in bfd/vms-alpha.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an out of bounds heap write and possibly achieve code execution via a crafted vms alpha file.

7.8 2017-08-04 CVE-2017-12449

The _bfd_vms_save_sized_string function in vms-misc.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an out of bounds heap read via a crafted vms file.

7.8 2017-08-04 CVE-2017-12448

The bfd_cache_close function in bfd/cache.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause a heap use after free and possibly achieve code execution via a crafted nested archive file. This issue occurs because incorrect functions are called during an attempt to release memory. The issue can be addressed by better input validation in the bfd_generic_archive_p function in bfd/archive.c.

9.8 2017-03-21 CVE-2014-9939

ihex.c in GNU Binutils before 2.26 contains a stack buffer overflow when printing bad bytes in Intel Hex objects.

5 2015-01-15 CVE-2014-8738

The _bfd_slurp_extended_name_table function in bfd/archive.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (invalid write, segmentation fault, and crash) via a crafted extended name table in an archive.

3.6 2014-12-09 CVE-2014-8737

Multiple directory traversal vulnerabilities in GNU binutils 2.24 and earlier allow local users to delete arbitrary files via a .. (dot dot) or full path name in an archive to (1) strip or (2) objcopy or create arbitrary files via (3) a .. (dot dot) or full path name in an archive to ar.

7.5 2014-12-09 CVE-2014-8504

Stack-based buffer overflow in the srec_scan function in bfd/srec.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly have other unspecified impact via a crafted file.

7.5 2014-12-09 CVE-2014-8503

Stack-based buffer overflow in the ihex_scan function in bfd/ihex.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly have other unspecified impact via a crafted ihex file.

7.5 2014-12-09 CVE-2014-8502

Heap-based buffer overflow in the pe_print_edata function in bfd/peXXigen.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly have other unspecified impact via a truncated export table in a PE file.

7.5 2014-12-09 CVE-2014-8501

The _bfd_XXi_swap_aouthdr_in function in bfd/peXXigen.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (out-of-bounds write) and possibly have other unspecified impact via a crafted NumberOfRvaAndSizes field in the AOUT header in a PE executable.

7.5 2014-12-09 CVE-2014-8485

The setup_group function in bfd/elf.c in libbfd in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted section group headers in an ELF file.

CWE : Common Weakness Enumeration

%idName
31% (9) CWE-125 Out-of-bounds Read
24% (7) CWE-119 Failure to Constrain Operations within the Bounds of a Memory Buffer
17% (5) CWE-787 Out-of-bounds Write
10% (3) CWE-190 Integer Overflow or Wraparound
3% (1) CWE-476 NULL Pointer Dereference
3% (1) CWE-416 Use After Free
3% (1) CWE-94 Failure to Control Generation of Code ('Code Injection')
3% (1) CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path ...
3% (1) CWE-20 Improper Input Validation

Nessus® Vulnerability Scanner

This CPE have more than 25 Relations. If you want to see a complete summary for this CPE, please contact us.
id Description
2018-08-17 Name: The remote PhotonOS host is missing multiple security updates.
File: PhotonOS_PHSA-2017-0010.nasl - Type: ACT_GATHER_INFO
2018-01-08 Name: The remote Gentoo host is missing one or more security-related patches.
File: gentoo_GLSA-201801-01.nasl - Type: ACT_GATHER_INFO
2017-12-14 Name: The remote openSUSE host is missing a security update.
File: openSUSE-2017-1330.nasl - Type: ACT_GATHER_INFO
2017-12-01 Name: The remote SUSE host is missing one or more security updates.
File: suse_SU-2017-3170-1.nasl - Type: ACT_GATHER_INFO
2017-07-27 Name: The remote Ubuntu host is missing a security-related patch.
File: ubuntu_USN-3367-1.nasl - Type: ACT_GATHER_INFO
2016-12-08 Name: The remote Gentoo host is missing one or more security-related patches.
File: gentoo_GLSA-201612-24.nasl - Type: ACT_GATHER_INFO
2015-12-22 Name: The remote Scientific Linux host is missing one or more security updates.
File: sl_20151119_binutils_on_SL7_x.nasl - Type: ACT_GATHER_INFO
2015-12-15 Name: The remote Amazon Linux AMI host is missing a security update.
File: ala_ALAS-2015-620.nasl - Type: ACT_GATHER_INFO
2015-12-02 Name: The remote CentOS host is missing one or more security updates.
File: centos_RHSA-2015-2079.nasl - Type: ACT_GATHER_INFO
2015-11-24 Name: The remote Oracle Linux host is missing one or more security updates.
File: oraclelinux_ELSA-2015-2079.nasl - Type: ACT_GATHER_INFO
2015-11-19 Name: The remote Red Hat host is missing one or more security updates.
File: redhat-RHSA-2015-2079.nasl - Type: ACT_GATHER_INFO
2015-03-30 Name: The remote Debian host is missing a security update.
File: debian_DLA-184.nasl - Type: ACT_GATHER_INFO
2015-03-25 Name: The remote FreeBSD host is missing one or more security-related updates.
File: freebsd_pkg_f6a014cdd26811e48339001e679db764.nasl - Type: ACT_GATHER_INFO
2015-02-10 Name: The remote Ubuntu host is missing one or more security-related patches.
File: ubuntu_USN-2496-1.nasl - Type: ACT_GATHER_INFO
2015-02-06 Name: The remote Mandriva Linux host is missing one or more security updates.
File: mandriva_MDVSA-2015-029.nasl - Type: ACT_GATHER_INFO
2015-01-29 Name: The remote SuSE 11 host is missing a security update.
File: suse_11_binutils-201501-150122.nasl - Type: ACT_GATHER_INFO
2015-01-22 Name: The remote Fedora host is missing a security update.
File: fedora_2015-0750.nasl - Type: ACT_GATHER_INFO
2015-01-22 Name: The remote Fedora host is missing a security update.
File: fedora_2015-0471.nasl - Type: ACT_GATHER_INFO
2015-01-12 Name: The remote Debian host is missing a security-related update.
File: debian_DSA-3123.nasl - Type: ACT_GATHER_INFO
2015-01-02 Name: The remote Fedora host is missing a security update.
File: fedora_2014-17603.nasl - Type: ACT_GATHER_INFO
2015-01-02 Name: The remote Fedora host is missing a security update.
File: fedora_2014-17586.nasl - Type: ACT_GATHER_INFO
2014-12-07 Name: The remote Fedora host is missing a security update.
File: fedora_2014-14995.nasl - Type: ACT_GATHER_INFO
2014-12-07 Name: The remote Fedora host is missing a security update.
File: fedora_2014-14888.nasl - Type: ACT_GATHER_INFO
2014-12-07 Name: The remote Fedora host is missing a security update.
File: fedora_2014-14874.nasl - Type: ACT_GATHER_INFO
2014-12-07 Name: The remote Fedora host is missing a security update.
File: fedora_2014-14838.nasl - Type: ACT_GATHER_INFO