SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-17451

It is an integer overflow leading to a SEGV in _bfd_dwarf2_find_nearest_line in dwarf2.c, as demonstrated by nm.

MEDIUM 6.5EPSS 2.40%

Does this matter?

Lower severity and a low EPSS score (2.40%). Track it; it rarely justifies an emergency change on its own.

Description

An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is an integer overflow leading to a SEGV in _bfd_dwarf2_find_nearest_line in dwarf2.c, as demonstrated by nm.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS
2.40% probability · 83th percentile
CISA KEV
Not listed
Weakness
CWE-190
Affected
gnu/binutils · opensuse/leap · canonical/ubuntu linux
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.