First published: Tue Jul 30 2019(Updated: )
apply_relocations in readelf.c in GNU Binutils 2.32 contains an integer overflow that allows attackers to trigger a write access violation (in byte_put_little_endian function in elfcomm.c) via an ELF file, as demonstrated by readelf.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNU Binutils | =2.32 | |
openSUSE Leap | =15.1 | |
openSUSE Leap | =15.2 | |
Canonical Ubuntu Linux | =18.04 | |
Netapp Hci Management Node | ||
Netapp Solidfire | ||
debian/binutils | 2.35.2-2 2.40-2 2.43.1-5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-14444 is a vulnerability in GNU Binutils 2.32 that allows attackers to trigger a write access violation via an ELF file.
CVE-2019-14444 affects GNU Binutils version 2.32 and earlier.
To fix CVE-2019-14444 in GNU Binutils, update to version 2.32.51.20190813-1 or later.
You can find more information about CVE-2019-14444 in the references provided: [sourceware.org](https://sourceware.org/bugzilla/show_bug.cgi?id=24829), [security.netapp.com](https://security.netapp.com/advisory/ntap-20190822-0002/), [usn.ubuntu.com](https://usn.ubuntu.com/4336-1/).
The Common Weakness Enumeration (CWE) ID for CVE-2019-14444 is CWE-190.