An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is an integer overflow leading to a SEGV in _bfd_dwarf2_find_nearest_line in dwarf2.c, as demonstrated by nm.
http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00078.html
http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00004.html
https://security.gentoo.org/glsa/202007-39
https://security.netapp.com/advisory/ntap-20191024-0002/
https://sourceware.org/bugzilla/show_bug.cgi?id=25070
https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=336bfbeb1848f4b9558456fdcf283ee8a32d7fd1
Source: MITRE
Published: 2019-10-10
Updated: 2020-11-02
Type: CWE-190
Base Score: 4.3
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P
Impact Score: 2.9
Exploitability Score: 8.6
Severity: MEDIUM
Base Score: 6.5
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Impact Score: 3.6
Exploitability Score: 2.8
Severity: MEDIUM
OR
ID | Name | Product | Family | Severity |
---|---|---|---|---|
146710 | EulerOS 2.0 SP2 : binutils (EulerOS-SA-2021-1282) | Nessus | Huawei Local Security Checks | medium |
145841 | CentOS 8 : binutils (CESA-2020:1797) | Nessus | CentOS Local Security Checks | medium |
143785 | SUSE SLES15 Security Update : binutils (SUSE-SU-2020:3552-1) | Nessus | SuSE Local Security Checks | medium |
143614 | SUSE SLED15 / SLES15 Security Update : binutils (SUSE-SU-2020:3060-1) | Nessus | SuSE Local Security Checks | medium |
140839 | EulerOS 2.0 SP3 : binutils (EulerOS-SA-2020-2072) | Nessus | Huawei Local Security Checks | medium |
138962 | GLSA-202007-39 : Binutils: Multiple vulnerabilities | Nessus | Gentoo Local Security Checks | medium |
136054 | RHEL 8 : binutils (RHSA-2020:1797) | Nessus | Red Hat Local Security Checks | medium |
135966 | Ubuntu 18.04 LTS : GNU binutils vulnerabilities (USN-4336-1) | Nessus | Ubuntu Local Security Checks | high |
135628 | EulerOS Virtualization 3.0.2.2 : binutils (EulerOS-SA-2020-1466) | Nessus | Huawei Local Security Checks | high |
134494 | EulerOS Virtualization for ARM 64 3.0.2.0 : binutils (EulerOS-SA-2020-1205) | Nessus | Huawei Local Security Checks | medium |
132828 | EulerOS Virtualization for ARM 64 3.0.5.0 : binutils (EulerOS-SA-2020-1074) | Nessus | Huawei Local Security Checks | medium |
132531 | Photon OS 2.0: Binutils PHSA-2019-2.0-0190 | Nessus | PhotonOS Local Security Checks | medium |
132521 | Photon OS 1.0: Binutils PHSA-2019-1.0-0257 | Nessus | PhotonOS Local Security Checks | medium |
131796 | EulerOS 2.0 SP5 : binutils (EulerOS-SA-2019-2522) | Nessus | Huawei Local Security Checks | medium |
131342 | EulerOS 2.0 SP8 : binutils (EulerOS-SA-2019-2276) | Nessus | Huawei Local Security Checks | medium |