First published: Sun Feb 24 2019(Updated: )
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is a heap-based buffer overflow in _bfd_archive_64_bit_slurp_armap in archive64.c.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNU Binutils | =2.32 | |
Netapp Hci Management Node | ||
Netapp Solidfire | ||
Canonical Ubuntu Linux | =18.04 | |
F5 BIG-IP Access Policy Manager | =14.1.0 | |
F5 BIG-IP Access Policy Manager | =15.0.0 | |
F5 BIG-IP Advanced Firewall Manager | =14.1.0 | |
F5 BIG-IP Advanced Firewall Manager | =15.0.0 | |
F5 BIG-IP Analytics | =14.1.0 | |
F5 BIG-IP Analytics | =15.0.0 | |
F5 Big-ip Application Acceleration Manager | =14.1.0 | |
F5 Big-ip Application Acceleration Manager | =15.0.0 | |
F5 BIG-IP Application Security Manager | =14.1.0 | |
F5 BIG-IP Application Security Manager | =15.0.0 | |
F5 Big-ip Domain Name System | =14.1.0 | |
F5 Big-ip Domain Name System | =15.0.0 | |
F5 Big-ip Edge Gateway | =14.1.0 | |
F5 Big-ip Edge Gateway | =15.0.0 | |
F5 Big-ip Fraud Protection Service | =14.1.0 | |
F5 Big-ip Fraud Protection Service | =15.0.0 | |
F5 Big-ip Global Traffic Manager | =14.1.0 | |
F5 Big-ip Global Traffic Manager | =15.0.0 | |
F5 Big-ip Link Controller | =14.1.0 | |
F5 Big-ip Link Controller | =15.0.0 | |
F5 Big-ip Local Traffic Manager | =14.1.0 | |
F5 Big-ip Local Traffic Manager | =15.0.0 | |
F5 Big-ip Policy Enforcement Manager | =14.1.0 | |
F5 Big-ip Policy Enforcement Manager | =15.0.0 | |
F5 Big-ip Policy Webaccelerator | =14.1.0 | |
F5 Big-ip Webaccelerator | =15.0.0 | |
debian/binutils | 2.35.2-2 2.40-2 2.43.50.20250108-1 2.43.90.20250122-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-9075 is high.
The affected software for CVE-2019-9075 is GNU Binutils version 2.32.
To fix CVE-2019-9075, update to version 2.35.2-2, 2.40-2, or 2.41-5 of the binutils package.
More information about CVE-2019-9075 can be found on the following sites: [link1](https://security.netapp.com/advisory/ntap-20190314-0003/), [link2](https://support.f5.com/csp/article/K42059040), [link3](https://sourceware.org/bugzilla/show_bug.cgi?id=24236).
The Common Weakness Enumeration (CWE) ID for CVE-2019-9075 is 119.