CVE-2019-9073 describes an attempted excessive memory allocation vulnerability in the Binary File Descriptor (BFD) library (libbfd), specifically within the _bfd_elf_slurp_version_tables function in elf.c, affecting GNU Binutils 2.32, Canonical, and NetApp products. Rated Medium (CVSS 5.5), this vulnerability requires user interaction and local access (AV:L/UI:R) to trigger a high availability impact (A:H) due to potential resource exhaustion. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage, indicating a low current threat landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.32CPE matchmatch criteria | cpe:2.3:a:gnu:binutils:2.32:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:hci_management_node:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:solidfire:-:*:*:*:*:*:*:* | ||
18.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2019-9073
Aug 11, 2020binutils: excessive memory allocation in function _bfd_elf_slurp_version_tables in elf.c
Feb 19, 2019An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd) as distributed in GNU Binutils 2.32. It is an attempted excessive memory allocation in _bfd_elf_slurp_version_tables in elf.c.
Feb 12, 2019