CVE-2019-9074: Medium severity binutils vulnerability
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is an out-of-bounds read leading to a SEGV in bfdgetl32 in libbfd.c, when called from pex64getruntimefunction in pei-x8664.c.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-9074?
CVE-2019-9074 is an issue in the Binary File Descriptor (BFD) library, as distributed in GNU Binutils 2.32, that leads to an out-of-bounds read and a SEGV in bfd_getl32.
What software is affected by CVE-2019-9074?
The affected software includes Ubuntu binutils 2.26.1-1ubuntu1~16.04.8+, Ubuntu binutils 2.30-21ubuntu1~18.04.3, Ubuntu binutils 2.33, and Debian binutils 2.31.1-16 through 2.35.2-2, 2.40-2, and 2.41-5.
How can I fix CVE-2019-9074 for Ubuntu binutils 2.26.1-1ubuntu1~16.04.8+?
To fix CVE-2019-9074 for Ubuntu binutils 2.26.1-1ubuntu1~16.04.8+, you should apply the remedy version 2.26.1-1ubuntu1~16.04.8+ provided by Ubuntu.
Where can I find more information about CVE-2019-9074?
You can find more information about CVE-2019-9074 from the following sources: [NetApp Security Advisory](https://security.netapp.com/advisory/ntap-20190314-0003/), [F5 Support Article](https://support.f5.com/csp/article/K09092524), and [Sourceware Bugzilla](https://sourceware.org/bugzilla/show_bug.cgi?id=24235).