CVE-2019-9075 is a heap-based buffer overflow vulnerability in the Binary File Descriptor (BFD) library (libbfd), specifically within the _bfd_archive_64_bit_slurp_armap function in archive64.c, affecting GNU Binutils 2.32 and products from Canonical, F5, and NetApp. This vulnerability carries a CVSS score of 7.8 (HIGH), indicating a local attack vector with low complexity, requiring user interaction, and potentially leading to high impacts on confidentiality, integrity, and availability. There is no evidence of active exploitation, no known public exploit code (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage, suggesting a low current threat landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.32CPE matchmatch criteria | cpe:2.3:a:gnu:binutils:2.32:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:hci_management_node:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:solidfire:-:*:*:*:*:*:*:* | ||
18.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:* | ||
14.1.0CPE matchmatch criteria | cpe:2.3:a:f5:big-ip_access_policy_manager:14.1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2019-9075
Aug 11, 2020binutils: heap-based buffer overflow in function _bfd_archive_64_bit_slurp_armap in archive64.c
Feb 19, 2019An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd) as distributed in GNU Binutils 2.32. It is a heap-based buffer overflow in _bfd_archive_64_bit_slurp_armap in archive64.c.
Feb 12, 2019