An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is an out-of-bounds read leading to a SEGV in bfd_getl32 in libbfd.c, when called from pex64_get_runtime_function in pei-x86_64.c.
http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00078.html
http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00004.html
https://security.netapp.com/advisory/ntap-20190314-0003/
https://sourceware.org/bugzilla/show_bug.cgi?id=24235
Source: MITRE
Published: 2019-02-24
Updated: 2020-11-02
Type: CWE-125
Base Score: 4.3
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P
Impact Score: 2.9
Exploitability Score: 8.6
Severity: MEDIUM
Base Score: 5.5
Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Impact Score: 3.6
Exploitability Score: 1.8
Severity: MEDIUM
OR
OR
cpe:2.3:a:netapp:element_software_management:*:*:*:*:*:*:*:*
ID | Name | Product | Family | Severity |
---|---|---|---|---|
143785 | SUSE SLES15 Security Update : binutils (SUSE-SU-2020:3552-1) | Nessus | SuSE Local Security Checks | medium |
143614 | SUSE SLED15 / SLES15 Security Update : binutils (SUSE-SU-2020:3060-1) | Nessus | SuSE Local Security Checks | medium |
136251 | EulerOS Virtualization for ARM 64 3.0.2.0 : binutils (EulerOS-SA-2020-1548) | Nessus | Huawei Local Security Checks | medium |
135966 | Ubuntu 18.04 LTS : GNU binutils vulnerabilities (USN-4336-1) | Nessus | Ubuntu Local Security Checks | high |
135628 | EulerOS Virtualization 3.0.2.2 : binutils (EulerOS-SA-2020-1466) | Nessus | Huawei Local Security Checks | high |
135150 | EulerOS Virtualization for ARM 64 3.0.6.0 : binutils (EulerOS-SA-2020-1363) | Nessus | Huawei Local Security Checks | medium |
133976 | EulerOS 2.0 SP8 : binutils (EulerOS-SA-2020-1142) | Nessus | Huawei Local Security Checks | medium |
133895 | EulerOS 2.0 SP5 : binutils (EulerOS-SA-2020-1094) | Nessus | Huawei Local Security Checks | medium |
132275 | EulerOS 2.0 SP3 : binutils (EulerOS-SA-2019-2558) | Nessus | Huawei Local Security Checks | high |
131604 | EulerOS 2.0 SP2 : binutils (EulerOS-SA-2019-2450) | Nessus | Huawei Local Security Checks | high |
126474 | Photon OS 3.0: Binutils PHSA-2019-3.0-0022 | Nessus | PhotonOS Local Security Checks | medium |
126185 | Photon OS 1.0: Binutils PHSA-2019-1.0-0239 | Nessus | PhotonOS Local Security Checks | high |