Alpine: binutils-avr: security update to 2.32-r0

high Tenable Self-Hosted Container Security Plugin ID 403689

Description

There are packages installed that are affected by multiple vulnerabilities referenced in the following CVEs:

- An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU
Binutils through 2.31. There is a heap-based buffer overflow in bfd_elf32_swap_phdr_in in elfcode.h
because the number of program headers is not restricted. (CVE-2018-19931)

- An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU
Binutils through 2.31. There is an integer overflow and infinite loop caused by the IS_CONTAINED_BY_LMA
macro in elf.c. (CVE-2018-19932)

- The _bfd_generic_read_minisymbols function in syms.c in the Binary File Descriptor (BFD) library (aka
libbfd), as distributed in GNU Binutils 2.31, has a memory leak via a crafted ELF file, leading to a
denial of service (memory consumption), as demonstrated by nm. (CVE-2018-20002)

- A heap-based buffer over-read exists in the function d_expression_1 in cp-demangle.c in GNU libiberty, as
distributed in GNU Binutils 2.31.1. A crafted input can cause segmentation faults, leading to denial-of-
service, as demonstrated by c++filt. (CVE-2018-20712)

See Also

https://security.alpinelinux.org/vuln/CVE-2018-19931

https://security.alpinelinux.org/vuln/CVE-2018-19932

https://security.alpinelinux.org/vuln/CVE-2018-20002

https://security.alpinelinux.org/vuln/CVE-2018-20712

Plugin Details

Severity: High

ID: 403689

Version: Revision 1.24

Type: Local

Published: 10/31/2023

Updated: 3/12/2025

Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.15

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2018-19931

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 7

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 12/7/2018

Reference Information

CVE: CVE-2018-19931, CVE-2018-19932, CVE-2018-20002, CVE-2018-20712

BID: 106142, 106144, 106563