{"id":"CVE-2019-12972","title":"An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32","summary":"An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. There is a heap-based buffer over-read in _bfd_doprnt in bfd.c because elf_object_p in elfcode.h mishandles an e_shstr…","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","cwe":["CWE-125"],"vendor":"gnu","product":"binutils","affected":["binutils = 2.32","leap = 15.1","leap = 15.2","ubuntu_linux = 18.04"],"published":"2019-06-26","updated":"2026-10-08","sourceUpdated":"2026-10-08T22:16:49.560","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2019-12972","references":[{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00078.html","label":"cve@mitre.org"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00004.html","label":"cve@mitre.org"},{"url":"http://www.securityfocus.com/bid/108903","label":"cve@mitre.org"},{"url":"https://security.gentoo.org/glsa/202007-39","label":"cve@mitre.org"},{"url":"https://sourceware.org/bugzilla/show_bug.cgi?id=24689","label":"cve@mitre.org"},{"url":"https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git%3Bh=890f750a3b053532a4b839a2dd6243076de12031","label":"cve@mitre.org"},{"url":"https://usn.ubuntu.com/4336-1/","label":"cve@mitre.org"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00078.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00004.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.securityfocus.com/bid/108903","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.gentoo.org/glsa/202007-39","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://sourceware.org/bugzilla/show_bug.cgi?id=24689","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git%3Bh=890f750a3b053532a4b839a2dd6243076de12031","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://usn.ubuntu.com/4336-1/","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.01802,"epssPercentile":0.77854,"ingestedAt":"2026-10-08T23:16:47.296Z","slug":"CVE-2019-12972","body":"## Overview\n\nAn issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. There is a heap-based buffer over-read in _bfd_doprnt in bfd.c because elf_object_p in elfcode.h mishandles an e_shstrndx section of type SHT_GROUP by omitting a trailing '\\0' character.\n\n## Affected\n\n- `binutils = 2.32`\n- `leap = 15.1`\n- `leap = 15.2`\n- `ubuntu_linux = 18.04`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":31,"depthScoreParts":{"impact":30.3,"likelihood":0.4,"exploitation":0,"ransomware":0},"changes":[]}