CVE-2019-14250

Description

An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. simple_object_elf_match in simple-object-elf.c does not check for a zero shstrndx value, leading to an integer overflow and resultant heap-based buffer overflow.

Risk Information

Base Score
5.5
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.19

Associated Vulnerability

VulnerabilityOS Platform
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP5 ) gcc9-debuginfo-9.2.1+r275327-1.3.9.x86_64.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP4 ) gcc9-debuginfo-9.2.1+r275327-1.3.9.x86_64_SP4.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP5 ) gcc9-debugsource-9.2.1+r275327-1.3.9.x86_64.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP4 ) gcc9-debugsource-9.2.1+r275327-1.3.9.x86_64_SP4.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP5 ) libasan5-9.2.1+r275327-1.3.9.x86_64.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP4 ) libasan5-9.2.1+r275327-1.3.9.x86_64_SP4.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP4 ) libasan5-32bit-9.2.1+r275327-1.3.9.x86_64.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP5 ) libasan5-32bit-9.2.1+r275327-1.3.9.x86_64_SP5.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP5 ) libasan5-debuginfo-9.2.1+r275327-1.3.9.x86_64.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP4 ) libasan5-debuginfo-9.2.1+r275327-1.3.9.x86_64_SP4.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP5 ) libatomic1-9.2.1+r275327-1.3.9.x86_64.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP4 ) libatomic1-9.2.1+r275327-1.3.9.x86_64_SP4.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP5 ) libatomic1-32bit-9.2.1+r275327-1.3.9.x86_64.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP4 ) libatomic1-32bit-9.2.1+r275327-1.3.9.x86_64_SP4.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP5 ) libatomic1-debuginfo-9.2.1+r275327-1.3.9.x86_64.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP4 ) libatomic1-debuginfo-9.2.1+r275327-1.3.9.x86_64_SP4.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP5 ) libgcc_s1-9.2.1+r275327-1.3.9.x86_64.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP5 ) libgcc_s1-32bit-9.2.1+r275327-1.3.9.x86_64.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP4 ) libgcc_s1-9.2.1+r275327-1.3.9.x86_64_SP4.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP4 ) libgcc_s1-32bit-9.2.1+r275327-1.3.9.x86_64_SP4.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP5 ) libgcc_s1-debuginfo-9.2.1+r275327-1.3.9.x86_64.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP4 ) libgcc_s1-debuginfo-9.2.1+r275327-1.3.9.x86_64_SP4.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP5 ) libgfortran5-9.2.1+r275327-1.3.9.x86_64.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP5 ) libgfortran5-32bit-9.2.1+r275327-1.3.9.x86_64.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP4 ) libgfortran5-9.2.1+r275327-1.3.9.x86_64_SP4.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP4 ) libgfortran5-32bit-9.2.1+r275327-1.3.9.x86_64_SP4.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP5 ) libgfortran5-debuginfo-9.2.1+r275327-1.3.9.x86_64.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP4 ) libgfortran5-debuginfo-9.2.1+r275327-1.3.9.x86_64_SP4.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP5 ) libgo14-9.2.1+r275327-1.3.9.x86_64.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP5 ) libgo14-32bit-9.2.1+r275327-1.3.9.x86_64.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP4 ) libgo14-9.2.1+r275327-1.3.9.x86_64_SP4.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP4 ) libgo14-32bit-9.2.1+r275327-1.3.9.x86_64_SP4.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP5 ) libgo14-debuginfo-9.2.1+r275327-1.3.9.x86_64.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP4 ) libgo14-debuginfo-9.2.1+r275327-1.3.9.x86_64_SP4.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP5 ) libgomp1-9.2.1+r275327-1.3.9.x86_64.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP5 ) libgomp1-32bit-9.2.1+r275327-1.3.9.x86_64.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP5 ) libgomp1-debuginfo-9.2.1+r275327-1.3.9.x86_64.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP4 ) libgomp1-9.2.1+r275327-1.3.9.x86_64_SP4.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP5 ) libitm1-9.2.1+r275327-1.3.9.x86_64.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP4 ) libgomp1-32bit-9.2.1+r275327-1.3.9.x86_64_SP4.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP5 ) libitm1-32bit-9.2.1+r275327-1.3.9.x86_64.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP5 ) libitm1-debuginfo-9.2.1+r275327-1.3.9.x86_64.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP4 ) libgomp1-debuginfo-9.2.1+r275327-1.3.9.x86_64_SP4.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP5 ) liblsan0-9.2.1+r275327-1.3.9.x86_64.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP4 ) libitm1-9.2.1+r275327-1.3.9.x86_64_SP4.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP5 ) liblsan0-debuginfo-9.2.1+r275327-1.3.9.x86_64.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP4 ) libitm1-32bit-9.2.1+r275327-1.3.9.x86_64_SP4.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP5 ) libquadmath0-9.2.1+r275327-1.3.9.x86_64.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP5 ) libquadmath0-32bit-9.2.1+r275327-1.3.9.x86_64.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP4 ) libitm1-debuginfo-9.2.1+r275327-1.3.9.x86_64_SP4.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP5 ) libquadmath0-debuginfo-9.2.1+r275327-1.3.9.x86_64.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP4 ) liblsan0-9.2.1+r275327-1.3.9.x86_64_SP4.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP5 ) libstdc++6-9.2.1+r275327-1.3.9.x86_64.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP4 ) liblsan0-debuginfo-9.2.1+r275327-1.3.9.x86_64_SP4.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP5 ) libstdc++6-32bit-9.2.1+r275327-1.3.9.x86_64.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP4 ) libquadmath0-9.2.1+r275327-1.3.9.x86_64_SP4.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP4 ) libquadmath0-32bit-9.2.1+r275327-1.3.9.x86_64_SP4.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP5 ) libstdc++6-debuginfo-9.2.1+r275327-1.3.9.x86_64.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP4 ) libquadmath0-debuginfo-9.2.1+r275327-1.3.9.x86_64_SP4.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP5 ) libstdc++6-locale-9.2.1+r275327-1.3.9.x86_64.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP4 ) libstdc++6-9.2.1+r275327-1.3.9.x86_64_SP4.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP4 ) libstdc++6-32bit-9.2.1+r275327-1.3.9.x86_64_SP4.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP5 ) libtsan0-9.2.1+r275327-1.3.9.x86_64.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP5 ) libtsan0-debuginfo-9.2.1+r275327-1.3.9.x86_64.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP4 ) libstdc++6-debuginfo-9.2.1+r275327-1.3.9.x86_64_SP4.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP5 ) libubsan1-9.2.1+r275327-1.3.9.x86_64.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP4 ) libstdc++6-locale-9.2.1+r275327-1.3.9.x86_64_SP4.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP5 ) libubsan1-32bit-9.2.1+r275327-1.3.9.x86_64.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP4 ) libtsan0-9.2.1+r275327-1.3.9.x86_64_SP4.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP4 ) libtsan0-debuginfo-9.2.1+r275327-1.3.9.x86_64_SP4.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP5 ) libubsan1-debuginfo-9.2.1+r275327-1.3.9.x86_64.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP4 ) libubsan1-9.2.1+r275327-1.3.9.x86_64_SP4.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP4 ) libubsan1-32bit-9.2.1+r275327-1.3.9.x86_64_SP4.rpmLinux
SUSE-SU-2020:0394-1(SUSE Linux Enterprise Server 12-SP4 ) libubsan1-debuginfo-9.2.1+r275327-1.3.9.x86_64_SP4.rpmLinux
library of utility functions used by GNU programs (USN-4326-1) libiberty-dev_20160215-1ubuntu0.3_i386.debLinux
library of utility functions used by GNU programs (USN-4326-1) libiberty-dev_20160215-1ubuntu0.3_amd64.debLinux
library of utility functions used by GNU programs (USN-4326-1) libiberty-dev_20170913-1ubuntu0.1_i386.debLinux
library of utility functions used by GNU programs (USN-4326-1) libiberty-dev_20170913-1ubuntu0.1_amd64.debLinux
GNU assembler, linker and binary utilities (USN-4336-1) binutils_2.30-21ubuntu1~18.04.3_i386.debLinux
GNU assembler, linker and binary utilities (USN-4336-1) binutils_2.30-21ubuntu1~18.04.3_amd64.debLinux
GNU assembler, linker and binary utilities (USN-4336-1) binutils-multiarch_2.30-21ubuntu1~18.04.3_i386.debLinux
GNU assembler, linker and binary utilities (USN-4336-1) binutils-multiarch_2.30-21ubuntu1~18.04.3_amd64.debLinux
SUSE-SU-2021:3593-1(SUSE Linux Enterprise Server 12-SP5 ) binutils-2.37-9.39.1.x86_64.rpmLinux
SUSE-SU-2021:3593-1(SUSE Linux Enterprise Server 12-SP5 ) binutils-debuginfo-2.37-9.39.1.x86_64.rpmLinux
SUSE-SU-2021:3593-1(SUSE Linux Enterprise Server 12-SP5 ) binutils-debugsource-2.37-9.39.1.x86_64.rpmLinux
SUSE-SU-2021:3593-1(SUSE Linux Enterprise Server 12-SP5 ) binutils-devel-2.37-9.39.1.x86_64.rpmLinux
SUSE-SU-2021:3593-1(SUSE Linux Enterprise Server 12-SP5 ) libctf-nobfd0-2.37-9.39.1.x86_64.rpmLinux
SUSE-SU-2021:3593-1(SUSE Linux Enterprise Server 12-SP5 ) libctf-nobfd0-debuginfo-2.37-9.39.1.x86_64.rpmLinux
SUSE-SU-2021:3593-1(SUSE Linux Enterprise Server 12-SP5 ) libctf0-2.37-9.39.1.x86_64.rpmLinux
SUSE-SU-2021:3593-1(SUSE Linux Enterprise Server 12-SP5 ) libctf0-debuginfo-2.37-9.39.1.x86_64.rpmLinux
SUSE-SU-2022:2015-1(SUSE Linux Enterprise Server 12-SP5 ) cpp48-4.8.5-31.26.1.x86_64.rpmLinux
SUSE-SU-2022:2015-1(SUSE Linux Enterprise Server 12-SP5 ) cpp48-debuginfo-4.8.5-31.26.1.x86_64.rpmLinux
SUSE-SU-2022:2015-1(SUSE Linux Enterprise Server 12-SP5 ) gcc48-4.8.5-31.26.1.x86_64.rpmLinux
SUSE-SU-2022:2015-1(SUSE Linux Enterprise Server 12-SP5 ) gcc48-32bit-4.8.5-31.26.1.x86_64.rpmLinux
SUSE-SU-2022:2015-1(SUSE Linux Enterprise Server 12-SP5 ) gcc48-c++-4.8.5-31.26.1.x86_64.rpmLinux
SUSE-SU-2022:2015-1(SUSE Linux Enterprise Server 12-SP5 ) gcc48-c++-debuginfo-4.8.5-31.26.1.x86_64.rpmLinux
SUSE-SU-2022:2015-1(SUSE Linux Enterprise Server 12-SP5 ) gcc48-debuginfo-4.8.5-31.26.1.x86_64.rpmLinux
SUSE-SU-2022:2015-1(SUSE Linux Enterprise Server 12-SP5 ) gcc48-debugsource-4.8.5-31.26.1.x86_64.rpmLinux
SUSE-SU-2022:2015-1(SUSE Linux Enterprise Server 12-SP5 ) gcc48-info-4.8.5-31.26.1.noarch.rpmLinux
SUSE-SU-2022:2015-1(SUSE Linux Enterprise Server 12-SP5 ) gcc48-locale-4.8.5-31.26.1.x86_64.rpmLinux
SUSE-SU-2022:2015-1(SUSE Linux Enterprise Server 12-SP5 ) libasan0-4.8.5-31.26.1.x86_64.rpmLinux
SUSE-SU-2022:2015-1(SUSE Linux Enterprise Server 12-SP5 ) libasan0-32bit-4.8.5-31.26.1.x86_64.rpmLinux
SUSE-SU-2022:2015-1(SUSE Linux Enterprise Server 12-SP5 ) libasan0-debuginfo-4.8.5-31.26.1.x86_64.rpmLinux
SUSE-SU-2022:2015-1(SUSE Linux Enterprise Server 12-SP5 ) libstdc++48-devel-4.8.5-31.26.1.x86_64.rpmLinux
SUSE-SU-2022:2015-1(SUSE Linux Enterprise Server 12-SP5 ) libstdc++48-devel-32bit-4.8.5-31.26.1.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234