Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
CVE-2025-7545 Details
Description
A vulnerability classified as problematic was found in GNU Binutils 2.45. Affected by this vulnerability is the function copy_section of the file binutils/objcopy.c. The manipulation leads to heap-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The patch is named 08c3cbe5926e4d355b5cb70bbec2b1eeb40c2944. It is recommended to apply a patch to fix this issue.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 14, 2025Exploitation: PocAutomatable: NoTechnical Impact: Partial
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert-portal.siemens.com/productcert/html/ssa-082556.html | siemens-SADP | |
| https://cert-portal.siemens.com/productcert/html/ssa-265688.html | siemens-SADP | |
| https://sourceware.org/bugzilla/show_bug.cgi?id=33049#c1 | CISA-ADP | Issue Tracking |
| https://sourceware.org/bugzilla/attachment.cgi?id=16117 | [email protected] | Broken Link |
| https://sourceware.org/bugzilla/show_bug.cgi?id=33049 | [email protected] | Issue Tracking |
| https://sourceware.org/bugzilla/show_bug.cgi?id=33049#c1 | [email protected] | Issue Tracking |
| https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=08c3cbe5926e4d355b5cb70bbec2b1eeb40c2944 | [email protected] | Broken Link |
| https://vuldb.com/?ctiid.316243 | [email protected] | Permissions RequiredVDB Entry |
| https://vuldb.com/?id.316243 | [email protected] | Third Party AdvisoryVDB Entry |
| https://vuldb.com/?submit.614355 | [email protected] | Third Party AdvisoryVDB Entry |
| https://www.gnu.org/ | [email protected] | Product |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-119 | Improper Restriction of Operations within the Bounds of a Memory Buffer | [email protected] |
| CWE-122 | Heap-based Buffer Overflow | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| gnu binutils | 2.45 |
CPE
Remediation
| |
Change History
8 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | siemens-SADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| May 12, 2026 | CVE Modified | siemens-SADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Jul 30, 2025 | Initial Analysis | [email protected] |
| Jul 15, 2025 | CVE Modified | CISA-ADP |
| Jul 13, 2025 | New CVE Received | [email protected] |