CVE-2019-9074

Related Vulnerabilities: CVE-2019-9074  

Impact: Moderate Public Date: 2019-02-19 CWE: CWE-119 Bugzilla: 1680665: CVE-2019-9074 binutils: out-of-bound read in function bfd_getl32 in libbfd.c An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is an out-of-bounds read leading to a SEGV in bfd_getl32 in libbfd.c, when called from pex64_get_runtime_function in pei-x86_64.c.

The MITRE CVE dictionary describes this issue as:

An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is an out-of-bounds read leading to a SEGV in bfd_getl32 in libbfd.c, when called from pex64_get_runtime_function in pei-x86_64.c.

Find out more about CVE-2019-9074 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v3 metrics

NOTE: The following CVSS v3 metrics and score provided are preliminary and subject to review.

CVSS3 Base Score 5.3
CVSS3 Base Metrics CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality Low
Integrity Impact Low
Availability Impact Low

Affected Packages State

Platform Package State
Red Hat Enterprise Linux 7 binutils Under investigation
Red Hat Enterprise Linux 6 binutils Under investigation
Red Hat Enterprise Linux 5 binutils Under investigation