CVE-2005-1704
published 2005-05-24CVE-2005-1704: Integer overflow in the Binary File Descriptor (BFD) library for gdb before 6.3, binutils, elfutils, and possibly other packages, allows user-assisted…
PriorityP417medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EPSS
0.60%
44.7th percentile
Integer overflow in the Binary File Descriptor (BFD) library for gdb before 6.3, binutils, elfutils, and possibly other packages, allows user-assisted attackers to execute arbitrary code via a crafted object file that specifies a large number of section headers, leading to a heap-based buffer overflow.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gdb | < gdb 6.3-6 (bookworm) | gdb 6.3-6 (bookworm) |
| gnu | gdb | <= 6.3 | — |
| gnu | gdb | >= 0 < 6.3-6 | 6.3-6 |
| gnu | gdb | >= 0 < 6.3-6 | 6.3-6 |
| gnu | gdb | >= 0 < 6.3-6 | 6.3-6 |
| gnu | gdb | >= 0 < 6.3-6 | 6.3-6 |
CVSS provenance
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv4.6MEDIUM
vendor_debian4.6MEDIUM
vendor_redhat4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
binutils vulnerability
vendor_ubuntu·2005-05-27
CVE-2005-1704 binutils vulnerability
Title: binutils vulnerability
Summary: binutils vulnerability
Tavis Ormandy found an integer overflow in the Binary File Descriptor
(BFD) parser in the GNU debugger. The same vulnerable code is also
present in binutils. By tricking an user into processing a specially
crafted executable with the binutils tools (strings, objdump, nm,
readelf, etc.), an attacker could exploit this to execute arbitrary
code with the privileges of the user running the affected program.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
gdb vulnerabilities
vendor_ubuntu·2005-05-27
CVE-2005-1704 gdb vulnerabilities
Title: gdb vulnerabilities
Summary: gdb vulnerabilities
Tavis Ormandy found an integer overflow in the GNU debugger. By
tricking an user into merely load a specially crafted executable, an
attacker could exploit this to execute arbitrary code with the
privileges of the user running gdb. However, loading untrusted
binaries without actually executing them is rather uncommon, so the
risk of this flaw is low. (CAN-2005-1704)
Tavis Ormandy also discovered that gdb loads and executes the file
".gdbinit" in the current directory even if the file belongs to a
different user. By tricking an user into run gdb in a directory with a
malicious .gdbinit file, a local attacker could exploit this to run
arbitrary commands with the privileges of the user invoking gdb.
(CAN-2005-1705)
Instructions: In g
Red Hat
security flaw
vendor_redhat·2005-05-25·CVSS 4.6
CVE-2005-1704 [MEDIUM] security flaw
security flaw
Integer overflow in the Binary File Descriptor (BFD) library for gdb before 6.3, binutils, elfutils, and possibly other packages, allows user-assisted attackers to execute arbitrary code via a crafted object file that specifies a large number of section headers, leading to a heap-based buffer overflow.
Statement: Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.
Debian
CVE-2005-1704: gdb - Integer overflow in the Binary File Descriptor (BFD) library for gdb before 6.3,...
vendor_debian·2005·CVSS 4.6
CVE-2005-1704 [MEDIUM] CVE-2005-1704: gdb - Integer overflow in the Binary File Descriptor (BFD) library for gdb before 6.3,...
Integer overflow in the Binary File Descriptor (BFD) library for gdb before 6.3, binutils, elfutils, and possibly other packages, allows user-assisted attackers to execute arbitrary code via a crafted object file that specifies a large number of section headers, leading to a heap-based buffer overflow.
Scope: local
bookworm: resolved (fixed in 6.3-6)
bullseye: resolved (fixed in 6.3-6)
forky: resolved (fixed in 6.3-6)
sid: resolved (fixed in 6.3-6)
trixie: resolved (fixed in 6.3-6)
GHSA
GHSA-r87q-q7hx-24jg: Integer overflow in the Binary File Descriptor (BFD) library for gdb before 6
ghsa_unreviewed·2022-05-03
CVE-2005-1704 [MEDIUM] GHSA-r87q-q7hx-24jg: Integer overflow in the Binary File Descriptor (BFD) library for gdb before 6
Integer overflow in the Binary File Descriptor (BFD) library for gdb before 6.3, binutils, elfutils, and possibly other packages, allows user-assisted attackers to execute arbitrary code via a crafted object file that specifies a large number of section headers, leading to a heap-based buffer overflow.
OSV
CVE-2005-1704: Integer overflow in the Binary File Descriptor (BFD) library for gdb before 6
osv·2005-05-24·CVSS 4.6
CVE-2005-1704 [MEDIUM] CVE-2005-1704: Integer overflow in the Binary File Descriptor (BFD) library for gdb before 6
Integer overflow in the Binary File Descriptor (BFD) library for gdb before 6.3, binutils, elfutils, and possibly other packages, allows user-assisted attackers to execute arbitrary code via a crafted object file that specifies a large number of section headers, leading to a heap-based buffer overflow.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2005-1704 security flaw
bugzilla·2018-08-16·CVSS 4.6
CVE-2005-1704 [MEDIUM] CVE-2005-1704 security flaw
CVE-2005-1704 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Integer overflow in the Binary File Descriptor (BFD) library for gdb before 6.3, binutils, elfutils, and possibly other packages, allows user-assisted attackers to execute arbitrary code via a crafted object file that specifies a large number of section headers, leading to a heap-based buffer overflow.
---
Statement:
Red Hat Enterprise Linux 5 is not vulnerable to this issue as it contains a backported patch.
Bugzilla
CVE-2005-1704 Integer overflow in libelf
bugzilla·2005-06-09·CVSS 4.6
CVE-2005-1704 [MEDIUM] CVE-2005-1704 Integer overflow in libelf
CVE-2005-1704 Integer overflow in libelf
+++ This bug was initially created as a clone of Bug #159888 +++
Integer overflow in libelf allows attackers to
execute arbitrary code via a crafted object file that specifies a large number
of section headers, leading to a heap-based buffer overflow.
Discussion:
Fixes are in 0.94.1-1 build.
---
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.
http://rhn.redhat.com/errata/RHSA-2006-0368.html
Bugzilla
CVE-2005-1704 Integer overflow in libelf
bugzilla·2005-06-08·CVSS 4.6
CVE-2005-1704 [MEDIUM] CVE-2005-1704 Integer overflow in libelf
CVE-2005-1704 Integer overflow in libelf
Integer overflow in the BFD library for libelf before 6.3 allows attackers to
execute arbitrary code via a crafted object file that specifies a large number
of section headers, leading to a heap-based buffer overflow.
Discussion:
This issue should also affect RHEL2.1 and RHEL3
---
elfutils is not in RHEL2.1, my mistake.
---
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.
http://rhn.redhat.com/errata/RHSA-2006-0354.html
ftp://patches.sgi.com/support/free/security/advisories/20060703-01-U.aschttp://bugs.gentoo.org/show_bug.cgi?id=91398http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=001060http://secunia.com/advisories/15527http://secunia.com/advisories/17001http://secunia.com/advisories/17072http://secunia.com/advisories/17135http://secunia.com/advisories/17257http://secunia.com/advisories/17356http://secunia.com/advisories/17718http://secunia.com/advisories/18506http://secunia.com/advisories/21122http://secunia.com/advisories/21262http://secunia.com/advisories/21717http://secunia.com/advisories/24788http://security.gentoo.org/glsa/glsa-200505-15.xmlhttp://securitytracker.com/id?1016544http://support.avaya.com/elmodocs2/security/ASA-2005-222.pdfhttp://support.avaya.com/elmodocs2/security/ASA-2006-015.htmhttp://support.avaya.com/elmodocs2/security/ASA-2006-178.htmhttp://www.gentoo.org/security/en/glsa/glsa-200506-01.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2005:095http://www.mandriva.com/security/advisories?name=MDKSA-2005:215http://www.osvdb.org/16757http://www.redhat.com/support/errata/RHSA-2005-659.htmlhttp://www.redhat.com/support/errata/RHSA-2005-673.htmlhttp://www.redhat.com/support/errata/RHSA-2005-709.htmlhttp://www.redhat.com/support/errata/RHSA-2005-763.htmlhttp://www.redhat.com/support/errata/RHSA-2005-801.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0354.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0368.htmlhttp://www.securityfocus.com/archive/1/464745/100/0/threadedhttp://www.securityfocus.com/bid/13697http://www.trustix.org/errata/2005/0025/http://www.vmware.com/support/vi3/doc/esx-55052-patch.htmlhttp://www.vupen.com/english/advisories/2007/1267https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9071https://usn.ubuntu.com/136-1/ftp://patches.sgi.com/support/free/security/advisories/20060703-01-U.aschttp://bugs.gentoo.org/show_bug.cgi?id=91398http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=001060http://secunia.com/advisories/15527http://secunia.com/advisories/17001http://secunia.com/advisories/17072http://secunia.com/advisories/17135http://secunia.com/advisories/17257http://secunia.com/advisories/17356http://secunia.com/advisories/17718http://secunia.com/advisories/18506http://secunia.com/advisories/21122http://secunia.com/advisories/21262http://secunia.com/advisories/21717http://secunia.com/advisories/24788http://security.gentoo.org/glsa/glsa-200505-15.xmlhttp://securitytracker.com/id?1016544http://support.avaya.com/elmodocs2/security/ASA-2005-222.pdfhttp://support.avaya.com/elmodocs2/security/ASA-2006-015.htmhttp://support.avaya.com/elmodocs2/security/ASA-2006-178.htmhttp://www.gentoo.org/security/en/glsa/glsa-200506-01.xmlhttp://www.mandriva.com/security/advisories?name=MDKSA-2005:095http://www.mandriva.com/security/advisories?name=MDKSA-2005:215http://www.osvdb.org/16757http://www.redhat.com/support/errata/RHSA-2005-659.htmlhttp://www.redhat.com/support/errata/RHSA-2005-673.htmlhttp://www.redhat.com/support/errata/RHSA-2005-709.htmlhttp://www.redhat.com/support/errata/RHSA-2005-763.htmlhttp://www.redhat.com/support/errata/RHSA-2005-801.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0354.htmlhttp://www.redhat.com/support/errata/RHSA-2006-0368.htmlhttp://www.securityfocus.com/archive/1/464745/100/0/threadedhttp://www.securityfocus.com/bid/13697http://www.trustix.org/errata/2005/0025/http://www.vmware.com/support/vi3/doc/esx-55052-patch.htmlhttp://www.vupen.com/english/advisories/2007/1267https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9071https://usn.ubuntu.com/136-1/
2005-05-24
Published