{"id":"CVE-2019-14250","title":"An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32","summary":"An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. simple_object_elf_match in simple-object-elf.c does not check for a zero shstrndx value, leading to an integer overflow and resultant heap-based buffer overflow.","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","cwe":["CWE-190","CWE-787"],"vendor":"gnu","product":"binutils","affected":["binutils = 2.32","ubuntu_linux = 16.04","ubuntu_linux = 18.04","leap = 15.0","leap = 15.1","leap = 15.2"],"published":"2019-07-24","updated":"2026-10-08","sourceUpdated":"2026-10-08T21:17:12.317","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2019-14250","references":[{"url":"http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00056.html","label":"cve@mitre.org"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00057.html","label":"cve@mitre.org"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00058.html","label":"cve@mitre.org"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00078.html","label":"cve@mitre.org"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00004.html","label":"cve@mitre.org"},{"url":"http://www.securityfocus.com/bid/109354","label":"cve@mitre.org"},{"url":"https://gcc.gnu.org/bugzilla/show_bug.cgi?id=90924","label":"cve@mitre.org"},{"url":"https://gcc.gnu.org/ml/gcc-patches/2019-07/msg01003.html","label":"cve@mitre.org"},{"url":"https://security.gentoo.org/glsa/202007-39","label":"cve@mitre.org"},{"url":"https://security.netapp.com/advisory/ntap-20190822-0002/","label":"cve@mitre.org"},{"url":"https://usn.ubuntu.com/4326-1/","label":"cve@mitre.org"},{"url":"https://usn.ubuntu.com/4336-1/","label":"cve@mitre.org"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00056.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00057.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00058.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00078.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00004.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.securityfocus.com/bid/109354","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://gcc.gnu.org/bugzilla/show_bug.cgi?id=90924","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://gcc.gnu.org/ml/gcc-patches/2019-07/msg01003.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.gentoo.org/glsa/202007-39","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20190822-0002/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://usn.ubuntu.com/4326-1/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://usn.ubuntu.com/4336-1/","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.02317,"epssPercentile":0.82904,"ingestedAt":"2026-10-08T22:11:53.698Z","slug":"CVE-2019-14250","body":"## Overview\n\nAn issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. simple_object_elf_match in simple-object-elf.c does not check for a zero shstrndx value, leading to an integer overflow and resultant heap-based buffer overflow.\n\n## Affected\n\n- `binutils = 2.32`\n- `ubuntu_linux = 16.04`\n- `ubuntu_linux = 18.04`\n- `leap = 15.0`\n- `leap = 15.1`\n- `leap = 15.2`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":31,"depthScoreParts":{"impact":30.3,"likelihood":0.5,"exploitation":0,"ransomware":0},"changes":[]}