PT-2005-1059 · Gnu+1 · Gdb+4

Ned Ludd

+1

·

Published

2005-05-24

·

Updated

2018-10-19

·

CVE-2005-1704

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions elfutils versions prior to 0.108 binutils version 2.11.90.0.8 gdb version 5.3.90
Description The issue affects the confidentiality, integrity, and availability of protected information. It can be exploited locally. The problem is caused by an integer overflow in the Binary File Descriptor (BFD) library, which allows user-assisted attackers to execute arbitrary code via a crafted object file. This can lead to a heap-based buffer overflow.
Recommendations For elfutils versions prior to 0.108, update to version 0.108 or later. For binutils version 2.11.90.0.8, update to a version that fixes the integer overflow issue in the BFD library. For gdb version 5.3.90, update to version 6.3 or later to fix the integer overflow issue in the BFD library. As a temporary workaround, consider restricting the use of the BFD library until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-05981
BDU:2015-06709
BDU:2015-09476
CVE-2005-1704
RHSA-2005:659
RHSA-2005:673
RHSA-2005:709
RHSA-2005_659
RHSA-2005_673
RHSA-2005_709
RHSA-2006:0354
RHSA-2006:0368
RHSA-2006_0354

Affected Products

Bfd Library
Red Hat
Binutils
Elfutils
Gdb