Vulnerability Description
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils through 2.31. There is an integer overflow and infinite loop caused by the IS_CONTAINED_BY_LMA macro in elf.c.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gnu | Binutils | <= 2.31 |
| Netapp | Vasa Provider | >= 7.2 |
| Netapp | Cluster Data Ontap | - |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00072.html
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00008.html
- http://www.securityfocus.com/bid/106144Third Party AdvisoryVDB Entry
- https://security.gentoo.org/glsa/201908-01
- https://security.netapp.com/advisory/ntap-20190221-0004/PatchThird Party Advisory
- https://sourceware.org/bugzilla/show_bug.cgi?id=23932ExploitIssue TrackingPatch
- https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git%3Bh=beab453223769279cc1
- https://usn.ubuntu.com/4336-1/
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00072.html
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00008.html
- http://www.securityfocus.com/bid/106144Third Party AdvisoryVDB Entry
- https://security.gentoo.org/glsa/201908-01
- https://security.netapp.com/advisory/ntap-20190221-0004/PatchThird Party Advisory
- https://sourceware.org/bugzilla/show_bug.cgi?id=23932ExploitIssue TrackingPatch
- https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git%3Bh=beab453223769279cc1
FAQ
What is CVE-2018-19932?
CVE-2018-19932 is a vulnerability with a CVSS score of 5.5 (MEDIUM). An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils through 2.31. There is an integer overflow and infinite loop caused by the IS_CONTAINED...
How severe is CVE-2018-19932?
CVE-2018-19932 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-19932?
Check the references section above for vendor advisories and patch information. Affected products include: Gnu Binutils, Netapp Vasa Provider, Netapp Cluster Data Ontap.