CVE-2019-17451: Integer Overflow
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is an integer overflow leading to a SEGV in bfddwarf2findnearestline in dwarf2.c, as demonstrated by nm.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-17451?
CVE-2019-17451 is an integer overflow vulnerability in the Binary File Descriptor (BFD) library, as distributed in GNU Binutils 2.32.
How does CVE-2019-17451 impact the affected software?
CVE-2019-17451 can lead to a SEGV (Segmentation Fault) in _bfd_dwarf2_find_nearest_line in dwarf2.c, resulting in a denial of service.
Which software versions are affected by CVE-2019-17451?
The affected software versions include Binutils 2.30-21ubuntu1~18.04.3 on Ubuntu 18.04.3, Binutils 2.26.1-1ubuntu1~16.04.8+ on Ubuntu 16.04.8+, and Binutils 2.31.1-16 on Debian.
How can I fix CVE-2019-17451?
To fix CVE-2019-17451, update to Binutils version 2.30-21ubuntu1~18.04.3 for Ubuntu 18.04.3, version 2.26.1-1ubuntu1~16.04.8+ for Ubuntu 16.04.8+, or version 2.31.1-16 for Debian.
Where can I find more information about CVE-2019-17451?
More information about CVE-2019-17451 can be found at the following references: [insert references here]