PT-2005-1059 · Gnu+1 · Gdb+4
Ned Ludd
+1
·
Published
2005-05-24
·
Updated
2018-10-19
·
CVE-2005-1704
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
elfutils versions prior to 0.108
binutils version 2.11.90.0.8
gdb version 5.3.90
Description
The issue affects the confidentiality, integrity, and availability of protected information. It can be exploited locally. The problem is caused by an integer overflow in the Binary File Descriptor (BFD) library, which allows user-assisted attackers to execute arbitrary code via a crafted object file. This can lead to a heap-based buffer overflow.
Recommendations
For elfutils versions prior to 0.108, update to version 0.108 or later.
For binutils version 2.11.90.0.8, update to a version that fixes the integer overflow issue in the BFD library.
For gdb version 5.3.90, update to version 6.3 or later to fix the integer overflow issue in the BFD library.
As a temporary workaround, consider restricting the use of the BFD library until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bfd Library
Red Hat
Binutils
Elfutils
Gdb