First published: Tue Aug 22 2023(Updated: )
Heap-based Buffer Overflow in function bfd_getl32 in Binutils objdump 3.37.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNU Binutils | <2.38 | |
debian/binutils | <=2.35.2-2 | 2.40-2 2.43.50.20250108-1 |
https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=cad4d6b91e97b6962807d33c04ed7e7797788438
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-46174 is a heap-based buffer overflow vulnerability in the bfd_getl32 function in Binutils objdump 3.37.
CVE-2021-46174 has a severity value of 7.5 (High).
The affected software include GNU Binutils, Ubuntu binutils (versions 2.30-21ubuntu1~18.04.9+ and 2.24-5ubuntu14.2+), and Debian binutils (versions up to and including 2.31.1-16 and 2.35.2-2).
To fix CVE-2021-46174, it is recommended to update to a version of Binutils that is not affected by the vulnerability.
You can find more information about CVE-2021-46174 in the following references: [1](https://sourceware.org/bugzilla/show_bug.cgi?id=28753) [2](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-46174) [3](https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=cad4d6b91e97b6962807d33c04ed7e7797788438)