PT-2014-8564 · Gnu+6 · Gnu Binutils+6

Published

2014-01-15

·

Updated

2018-01-03

·

CVE-2014-8501

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions GNU binutils versions 2.24 and earlier
Description The issue allows remote attackers to cause a denial of service (out-of-bounds write) and possibly have other unspecified impact via a crafted NumberOfRvaAndSizes field in the AOUT header in a PE executable. This is due to the bfd XXi swap aouthdr in function in bfd/peXXigen.c.
Recommendations For GNU binutils versions 2.24 and earlier, consider updating to a newer version to mitigate the risk. As a temporary workaround, restrict the use of the bfd XXi swap aouthdr in function in bfd/peXXigen.c to minimize the risk of exploitation. Avoid using crafted NumberOfRvaAndSizes fields in the AOUT header in PE executables until the issue is resolved.

Exploit

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-1061
ALT-PU-2016-1015
CESA-2015_2079
CVE-2014-8501
DLA-184-1
DSA-3123-1
DSA-3123-2
ECHO-418F-AAAE-0CBD
MGASA-2015-0027
MGASA-2018-0034
RHSA-2015:2079
RHSA-2015_2079
USN-2496-1
USN-3367-1

Affected Products

Alt Linux
Centos
Debian
Gnu Binutils
Red Hat
Suse
Ubuntu