Vulnerability Description
GNU binutils gold gold v1.11-v1.16 (GNU binutils v2.21-v2.31.1) is affected by: Improper Input Validation, Signed/Unsigned Comparison, Out-of-bounds Read. The impact is: Denial of service. The component is: gold/fileread.cc:497, elfcpp/elfcpp_file.h:644. The attack vector is: An ELF file with an invalid e_shoff header field must be opened.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gnu | Binutils | >= 2.21, <= 2.31.1 |
| Gnu | Binutils Gold | >= 1.11, <= 1.16 |
| Netapp | Hci Management Node | - |
| Netapp | Solidfire | - |
Related Weaknesses (CWE)
References
- https://security.netapp.com/advisory/ntap-20190822-0001/Third Party Advisory
- https://sourceware.org/bugzilla/show_bug.cgi?id=23765Issue TrackingThird Party Advisory
- https://support.f5.com/csp/article/K05032915?utm_source=f5support&%3Butm_medi
- https://security.netapp.com/advisory/ntap-20190822-0001/Third Party Advisory
- https://sourceware.org/bugzilla/show_bug.cgi?id=23765Issue TrackingThird Party Advisory
- https://support.f5.com/csp/article/K05032915?utm_source=f5support&%3Butm_medi
FAQ
What is CVE-2019-1010204?
CVE-2019-1010204 is a vulnerability with a CVSS score of 5.5 (MEDIUM). GNU binutils gold gold v1.11-v1.16 (GNU binutils v2.21-v2.31.1) is affected by: Improper Input Validation, Signed/Unsigned Comparison, Out-of-bounds Read. The impact is: Denial of service. The compone...
How severe is CVE-2019-1010204?
CVE-2019-1010204 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-1010204?
Check the references section above for vendor advisories and patch information. Affected products include: Gnu Binutils, Gnu Binutils Gold, Netapp Hci Management Node, Netapp Solidfire.