PT-2014-8564 · Gnu+6 · Gnu Binutils+6

Publicado

2014-01-15

·

Atualizado

2018-01-03

·

CVE-2014-8501

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions GNU binutils versions 2.24 and earlier
Description The issue allows remote attackers to cause a denial of service (out-of-bounds write) and possibly have other unspecified impact via a crafted NumberOfRvaAndSizes field in the AOUT header in a PE executable. This is due to the bfd XXi swap aouthdr in function in bfd/peXXigen.c.
Recommendations For GNU binutils versions 2.24 and earlier, consider updating to a newer version to mitigate the risk. As a temporary workaround, restrict the use of the bfd XXi swap aouthdr in function in bfd/peXXigen.c to minimize the risk of exploitation. Avoid using crafted NumberOfRvaAndSizes fields in the AOUT header in PE executables until the issue is resolved.

Exploit

Correção

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2014-1061
ALT-PU-2016-1015
CESA-2015_2079
CVE-2014-8501
DLA-184-1
DSA-3123-1
DSA-3123-2
ECHO-418F-AAAE-0CBD
MGASA-2015-0027
MGASA-2018-0034
RHSA-2015:2079
RHSA-2015_2079
USN-2496-1
USN-3367-1

Produtos afetados

Alt Linux
Centos
Debian
Gnu Binutils
Red Hat
Suse
Ubuntu