Integer Overflow or Wraparound

Affecting binutils package, versions *

Report new vulnerabilities
Do your applications use this vulnerable package? Test your applications

Overview

An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is an integer overflow leading to a SEGV in _bfd_dwarf2_find_nearest_line in dwarf2.c, as demonstrated by nm.

References

CVSS Score

6.5
low severity
  • Attack Vector
    Network
  • Attack Complexity
    Low
  • Privileges Required
    None
  • User Interaction
    Required
  • Scope
    Unchanged
  • Confidentiality
    None
  • Integrity
    None
  • Availability
    High
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVE
CVE-2019-17451
CWE
CWE-190
Snyk ID
SNYK-DEBIAN9-BINUTILS-472899
Disclosed
10 Oct, 2019
Published
10 Oct, 2019