CVE-2024-53589
Publication date 5 December 2024
Last updated 20 January 2025
Ubuntu priority
GNU objdump 2.43 is vulnerable to Buffer Overflow in the BFD (Binary File Descriptor) library's handling of tekhex format files.
Status
Package | Ubuntu Release | Status |
---|---|---|
binutils | 24.10 oracular |
Not affected
|
24.04 LTS noble |
Not affected
|
|
22.04 LTS jammy |
Not affected
|
|
20.04 LTS focal |
Not affected
|
|
18.04 LTS bionic |
Not affected
|
|
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty | Ignored end of ESM support, was needs-triage |
Notes
seth-arnold
binutils isn't safe for untrusted inputs.
mdeslaur
only affected 2.43, introduced in: https://sourceware.org/git/?p=binutils-gdb.git;a=commit;h=8b5a212495
Patch details
Package | Patch details |
---|---|
binutils |