CVE-2019-14444 PUBLISHED

apply_relocations in readelf.c in GNU Binutils 2.32 contains an integer overflow that allows attackers to trigger a write access violation (in byte_put_little_endian function in elfcomm.c) via an ELF file, as demonstrated by readelf.

EPSS 0.43% · 62.3th percentile

Risk Scores

EPSS Score
0.43%
62.3th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:16.04:LTSbinutils2.25.51.20151113-2ubuntu1, 0, 2.26-8ubuntu2.1
Ubuntu:18.04:LTSbinutils2.29.1-12ubuntu1, 2.29.1-4ubuntu1, 2.29.1-7ubuntu1
Ubuntu:Pro:14.04:LTSbinutils2.24-1ubuntu2, 2.24-1ubuntu1, 2.23.91.20131123-1ubuntu1

Timeline

References

Open in Interactive Console →