CVE-2019-9070: High severity GNU binutils vulnerability
An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. It is a heap-based buffer over-read in dexpression1 in cp-demangle.c after many recursive calls.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/binutilsto a version that resolves this vulnerability.Fixed in 2.35.2-2Fixed in 2.40-2Fixed in 2.44-3Fixed in 2.46.90.20260712-1
Event History
Frequently Asked Questions
What is CVE-2019-9070?
CVE-2019-9070 is a heap-based buffer over-read vulnerability in GNU libiberty as distributed in GNU Binutils 2.32.
What is the severity of CVE-2019-9070?
CVE-2019-9070 has a severity rating of 7.8 (High).
How does CVE-2019-9070 affect GNU Binutils?
CVE-2019-9070 affects GNU Binutils version 2.32.
Where can I find more information about CVE-2019-9070?
You can find more information about CVE-2019-9070 at the following references: [http://www.securityfocus.com/bid/107147](http://www.securityfocus.com/bid/107147), [https://security.netapp.com/advisory/ntap-20190314-0003/](https://security.netapp.com/advisory/ntap-20190314-0003/), [https://support.f5.com/csp/article/K13534168](https://support.f5.com/csp/article/K13534168).
How can I fix the CVE-2019-9070 vulnerability?
To fix the CVE-2019-9070 vulnerability, you should update GNU Binutils to a version higher than 2.32.