CVE-2018-19932

MEDIUM

GNU Binutils - Integer Overflow

Title source: llm

Description

An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils through 2.31. There is an integer overflow and infinite loop caused by the IS_CONTAINED_BY_LMA macro in elf.c.

Scores

CVSS v3 5.5
EPSS 0.0042
EPSS Percentile 61.6%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Classification

CWE
CWE-190
Status published

Affected Products (2)

gnu/binutils < 2.31
netapp/vasa_provider

Timeline

Published Dec 07, 2018
Tracked Since Feb 18, 2026