Out-of-bounds read in Binutils - CVE-2019-9074

 

Out-of-bounds read in Binutils - CVE-2019-9074

Published: August 1, 2019 / Updated: January 21, 2020


Vulnerability identifier: #VU19611
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-9074
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a boundary condition in bfd_getl32() function in libbfd.c within the libbfd library, distributed in GNU Binutils. A remote attacker can create a specially crafted Excel file, trick the victim into opening it, trigger out-of-bounds read error and read contents of memory on the system.


Affected software

Binutils
Gentoo Linux
SUSE OpenStack Cloud Crowbar
SUSE OpenStack Cloud
HPE Helion Openstack
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Software Development Kit
Opensuse
sys-devel/binutils
libctf0-debuginfo
cross-spu-binutils-debugsource
cross-spu-binutils-debuginfo
cross-spu-binutils
cross-ppc-binutils-debugsource
cross-ppc-binutils-debuginfo
cross-ppc-binutils
binutils-gold-debuginfo
binutils-gold
libctf0
libctf-nobfd0-debuginfo
libctf-nobfd0
binutils-devel
binutils-debugsource
binutils-debuginfo
binutils
Robotic Process Automation for Cloud Pak

How to mitigate CVE-2019-9074

Install update from vendor's website.

Binutils - update to 2.33.1
sys-devel/binutils - update to 2.35.2
libctf0-debuginfo - update to 2.37-9.39.1
cross-spu-binutils-debugsource - update to 2.37-9.39.1
cross-spu-binutils-debuginfo - update to 2.37-9.39.1
cross-spu-binutils - update to 2.37-9.39.1
cross-ppc-binutils-debugsource - update to 2.37-9.39.1
cross-ppc-binutils-debuginfo - update to 2.37-9.39.1
cross-ppc-binutils - update to 2.37-9.39.1
binutils-gold-debuginfo - update to 2.37-9.39.1
binutils-gold - update to 2.37-9.39.1
libctf0 - update to 2.37-9.39.1
libctf-nobfd0-debuginfo - update to 2.37-9.39.1
libctf-nobfd0 - update to 2.37-9.39.1
binutils-devel - update to 2.37-9.39.1
binutils-debugsource - update to 2.37-9.39.1
binutils-debuginfo - update to 2.37-9.39.1
binutils - update to 2.37-9.39.1
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.2, 23.0.3

External References

Related Security Bulletins