First published: Fri Dec 07 2018(Updated: )
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils through 2.31. There is a heap-based buffer overflow in bfd_elf32_swap_phdr_in in elfcode.h because the number of program headers is not restricted.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNU Binutils | <=2.31 | |
Netapp Vasa Provider Clustered Data Ontap | >=7.2 | |
Canonical Ubuntu Linux | =18.04 | |
debian/binutils | 2.35.2-2 2.40-2 2.43.1-5 |
https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=5f60af5d24d181371d67534fa273dd221df20c07
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-19931 is a vulnerability in the Binary File Descriptor (BFD) library (aka libbfd) as distributed in GNU Binutils through version 2.31, which can lead to a heap-based buffer overflow in bfd_elf32_swap_phdr_in in elfcode.h.
CVE-2018-19931 affects systems that have the affected version of GNU Binutils installed, specifically versions up to and including 2.31.
The severity of CVE-2018-19931 is not specified in the provided information.
To fix CVE-2018-19931, users should update their GNU Binutils to a version that is not affected. Refer to the provided references for specific version numbers and updates.
You can find more information about CVE-2018-19931 in the provided references: [https://sourceware.org/bugzilla/show_bug.cgi?id=23942](https://sourceware.org/bugzilla/show_bug.cgi?id=23942), [https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=5f60af5d24d181371d67534fa273dd221df20c07](https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=5f60af5d24d181371d67534fa273dd221df20c07), [http://www.securityfocus.com/bid/106144](http://www.securityfocus.com/bid/106144).