Product:

Binutils

(Gnu)
Repositories

Unknown:

This might be proprietary software.

#Vulnerabilities 224
Date Id Summary Products Score Patch Annotated
2023-08-22 CVE-2022-48064 GNU Binutils before 2.40 was discovered to contain an excessive memory consumption vulnerability via the function bfd_dwarf2_find_nearest_line_with_alt at dwarf2.c. The attacker could supply a crafted ELF file and cause a DNS attack. Fedora, Binutils, Ontap_select_deploy_administration_utility 5.5
2023-08-22 CVE-2022-48065 GNU Binutils before 2.40 was discovered to contain a memory leak vulnerability var the function find_abstract_instance in dwarf2.c. Fedora, Binutils, Ontap_select_deploy_administration_utility 5.5
2023-09-14 CVE-2023-25584 An out-of-bounds read flaw was found in the parse_module function in bfd/vms-alpha.c in Binutils. Binutils 7.1
2023-09-14 CVE-2023-25585 A flaw was found in Binutils. The use of an uninitialized field in the struct module *module may lead to application crash and local denial of service. Binutils 5.5
2023-09-14 CVE-2023-25586 A flaw was found in Binutils. A logic fail in the bfd_init_section_decompress_status function may lead to the use of an uninitialized variable that can cause a crash and local denial of service. Binutils 5.5
2023-09-14 CVE-2023-25588 A flaw was found in Binutils. The field `the_bfd` of `asymbol`struct is uninitialized in the `bfd_mach_o_get_synthetic_symtab` function, which may lead to an application crash and local denial of service. Binutils 5.5
2006-05-15 CVE-2006-2362 Buffer overflow in getsym in tekhex.c in libbfd in Free Software Foundation GNU Binutils before 20060423, as used by GNU strings, allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a file with a crafted Tektronix Hex Format (TekHex) record in which the length character is not a valid hexadecimal character. Binutils N/A
2014-12-09 CVE-2014-8484 The srec_scan function in bfd/srec.c in libdbfd in GNU binutils before 2.25 allows remote attackers to cause a denial of service (out-of-bounds read) via a small S-record. Ubuntu_linux, Fedora, Binutils N/A
2014-12-09 CVE-2014-8485 The setup_group function in bfd/elf.c in libbfd in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted section group headers in an ELF file. Ubuntu_linux, Fedora, Binutils N/A
2014-12-09 CVE-2014-8501 The _bfd_XXi_swap_aouthdr_in function in bfd/peXXigen.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (out-of-bounds write) and possibly have other unspecified impact via a crafted NumberOfRvaAndSizes field in the AOUT header in a PE executable. Ubuntu_linux, Fedora, Binutils N/A