First published: Sun Feb 24 2019(Updated: )
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is an out-of-bounds read leading to a SEGV in bfd_getl32 in libbfd.c, when called from pex64_get_runtime_function in pei-x86_64.c.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ubuntu/binutils | =2.32 | |
netapp hci management node | ||
netapp solidfire | ||
Ubuntu Linux | =18.04 | |
debian/binutils | 2.35.2-2 2.40-2 2.44-1 | |
GNU Binutils | =2.32 | |
Ubuntu | =18.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-9074 is an issue in the Binary File Descriptor (BFD) library, as distributed in GNU Binutils 2.32, that leads to an out-of-bounds read and a SEGV in bfd_getl32.
The affected software includes Ubuntu binutils 2.26.1-1ubuntu1~16.04.8+, Ubuntu binutils 2.30-21ubuntu1~18.04.3, Ubuntu binutils 2.33, and Debian binutils 2.31.1-16 through 2.35.2-2, 2.40-2, and 2.41-5.
To fix CVE-2019-9074 for Ubuntu binutils 2.26.1-1ubuntu1~16.04.8+, you should apply the remedy version 2.26.1-1ubuntu1~16.04.8+ provided by Ubuntu.
You can find more information about CVE-2019-9074 from the following sources: [NetApp Security Advisory](https://security.netapp.com/advisory/ntap-20190314-0003/), [F5 Support Article](https://support.f5.com/csp/article/K09092524), and [Sourceware Bugzilla](https://sourceware.org/bugzilla/show_bug.cgi?id=24235).