CVE-2018-19932

MEDIUM

GNU Binutils < 2.31 - Integer Overflow and Infinite Loop in BFD Library

Title source: llm
STIX 2.1

Description

An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils through 2.31. There is an integer overflow and infinite loop caused by the IS_CONTAINED_BY_LMA macro in elf.c.

References (8)

Core 8
Core References
Patch, Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20190221-0004/
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/106144
Exploit, Issue Tracking, Patch x_refsource_misc
https://sourceware.org/bugzilla/show_bug.cgi?id=23932
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/201908-01
Vendor Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/4336-1/

Scores

CVSS v3 5.5
EPSS 0.0042
EPSS Percentile 62.1%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Details

CWE
CWE-190
Status published
Products (2)
gnu/binutils < 2.31
netapp/vasa_provider 7.2
Published Dec 07, 2018
Tracked Since Feb 18, 2026