Do your applications use this vulnerable package?
Test your applications
Overview
An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. simple_object_elf_match in simple-object-elf.c does not check for a zero shstrndx value, leading to an integer overflow and resultant heap-based buffer overflow.
References
CVSS Score
5.5
low severity
-
Attack VectorLocal
-
Attack ComplexityLow
-
Privileges RequiredNone
-
User InteractionRequired
-
ScopeUnchanged
-
ConfidentialityHigh
-
IntegrityNone
-
AvailabilityNone
- CVE
- CVE-2019-14250
- CWE
- CWE-190 CWE-787
- Snyk ID
- SNYK-DEBIAN10-BINUTILS-455454
- Disclosed
- 24 Jul, 2019
- Published
- 25 Jul, 2019