USN-6544-1
Dashboard / Vulnerabilities / USN-6544-1
USN-6544-1
Summary: binutils vulnerabilities
Details: It was discovered that GNU binutils incorrectly handled certain COFF files. An attacker could possibly use this issue to cause a crash or execute arbitrary code. This issue only affected Ubuntu 14.04 LTS. (CVE-2022-38533) It was discovered that GNU binutils was not properly performing bounds checks in several functions, which could lead to a buffer overflow. An attacker could possibly use this issue to cause a denial of service, expose sensitive information or execute arbitrary code. This issue only affected Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2022-4285, CVE-2020-19726, CVE-2021-46174) It was discovered that GNU binutils contained a reachable assertion, which could lead to an intentional assertion failure when processing certain crafted DWARF files. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2022-35205)
References: https://ubuntu.com/security/notices/USN-6544-1, https://ubuntu.com/security/CVE-2020-19726, https://ubuntu.com/security/CVE-2021-46174, https://ubuntu.com/security/CVE-2022-4285, https://ubuntu.com/security/CVE-2022-35205, https://ubuntu.com/security/CVE-2022-38533
Affected packages
Package
Name: binutils
Purl: pkg:deb/ubuntu/binutils?arch=source&distro=trusty%2Fesm
Affected ranges
Type: ECOSYSTEM
Events:
