GNU Binutils Denial of Service and Heap Buffer Overflow Vulnerabilities
BID:107412
Info
GNU Binutils Denial of Service and Heap Buffer Overflow Vulnerabilities
| Bugtraq ID: | 107412 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2019-9072 CVE-2019-9073 CVE-2019-9074 CVE-2019-9075 CVE-2019-9076 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 23 2019 12:00AM |
| Updated: | Feb 23 2019 12:00AM |
| Credit: | spinpx |
| Vulnerable: |
GNU Binutils 2.32 |
| Not Vulnerable: | |
Discussion
GNU Binutils Denial of Service and Heap Buffer Overflow Vulnerabilities
GNU Binutils is prone to multiple denial-of-service vulnerabilities and a heap-based buffer-overflow vulnerability
Attackers can exploit these issues to execute arbitrary code within the context of the affected application. Failed exploit attempts may result in denial-of-service conditions.
Binutils 2.32 is vulnerable; other versions may also be vulnerable.
GNU Binutils is prone to multiple denial-of-service vulnerabilities and a heap-based buffer-overflow vulnerability
Attackers can exploit these issues to execute arbitrary code within the context of the affected application. Failed exploit attempts may result in denial-of-service conditions.
Binutils 2.32 is vulnerable; other versions may also be vulnerable.
Exploit / POC
GNU Binutils Denial of Service and Heap Buffer Overflow Vulnerabilities
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.
Solution / Fix
GNU Binutils Denial of Service and Heap Buffer Overflow Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
GNU Binutils Denial of Service and Heap Buffer Overflow Vulnerabilities
References:
References:
- GNU Homepage (GNU)
- Bug 24232 - objdump: Out of memory in objalloc.c (Sourceware)
- Bug 24233 - objdump: Out of memory in libbfd.c (Sourceware)
- Bug 24235 - objdump: Read memory violation in libbfd.c (Sourceware)
- Bug 24236 - size: Heap buffer overflow in _bfd_archive_64_bit_slurp_armap (Sourceware)
- Bug 24237 - size: Out of memory in objalloc.c (Sourceware)
- Bug 24238 - size: Out of memory in libbfd (Sourceware)
- Bug 89396 - objdump: Out of memory in objalloc.c (libiberty) (GNU)