CVE-2005-4807
published 2005-12-31CVE-2005-4807: Stack-based buffer overflow in the as_bad function in messages.c in the GNU as (gas) assembler in Free Software Foundation GNU Binutils before 20050721 allows…
PriorityP341high7.5CVSS 2.0
AVNACLAuNCPIPAP
EXPLOIT
EPSS
11.92%
95.6th percentile
Stack-based buffer overflow in the as_bad function in messages.c in the GNU as (gas) assembler in Free Software Foundation GNU Binutils before 20050721 allows attackers to execute arbitrary code via a .c file with crafted inline assembly code.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | binutils | < binutils 2.17-1 (bookworm) | binutils 2.17-1 (bookworm) |
| gnu | binutils | < 2.17 | 2.17 |
| gnu | binutils | >= 0 < 2.17-1 | 2.17-1 |
| gnu | binutils | >= 0 < 2.17-1 | 2.17-1 |
| gnu | binutils | >= 0 < 2.17-1 | 2.17-1 |
| gnu | binutils | >= 0 < 2.17-1 | 2.17-1 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5LOW
vendor_redhat7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2005-4807: binutils - Stack-based buffer overflow in the as_bad function in messages.c in the GNU as (...
vendor_debian·2005·CVSS 7.5
CVE-2005-4807 [HIGH] CVE-2005-4807: binutils - Stack-based buffer overflow in the as_bad function in messages.c in the GNU as (...
Stack-based buffer overflow in the as_bad function in messages.c in the GNU as (gas) assembler in Free Software Foundation GNU Binutils before 20050721 allows attackers to execute arbitrary code via a .c file with crafted inline assembly code.
Scope: local
bookworm: resolved (fixed in 2.17-1)
bullseye: resolved (fixed in 2.17-1)
forky: resolved (fixed in 2.17-1)
sid: resolved (fixed in 2.17-1)
trixie: resolved (fixed in 2.17-1)
Red Hat
CVE-2005-4807: Stack-based buffer overflow in the as_bad function in messages
vendor_redhat·CVSS 7.5
CVE-2005-4807 [HIGH] CVE-2005-4807: Stack-based buffer overflow in the as_bad function in messages
Stack-based buffer overflow in the as_bad function in messages.c in the GNU as (gas) assembler in Free Software Foundation GNU Binutils before 20050721 allows attackers to execute arbitrary code via a .c file with crafted inline assembly code.
Statement: gas (and gcc) make no promise that they are fault tolerant to bad input. We do not plan on producing security updates for Red Hat Enterprise Linux to correct these bugs.
GHSA
GHSA-f884-r5wp-g6v3: Stack-based buffer overflow in the as_bad function in messages
ghsa_unreviewed·2022-05-01
CVE-2005-4807 [HIGH] CWE-119 GHSA-f884-r5wp-g6v3: Stack-based buffer overflow in the as_bad function in messages
Stack-based buffer overflow in the as_bad function in messages.c in the GNU as (gas) assembler in Free Software Foundation GNU Binutils before 20050721 allows attackers to execute arbitrary code via a .c file with crafted inline assembly code.
OSV
CVE-2005-4807: Stack-based buffer overflow in the as_bad function in messages
osv·2005-12-31·CVSS 7.5
CVE-2005-4807 [HIGH] CVE-2005-4807: Stack-based buffer overflow in the as_bad function in messages
Stack-based buffer overflow in the as_bad function in messages.c in the GNU as (gas) assembler in Free Software Foundation GNU Binutils before 20050721 allows attackers to execute arbitrary code via a .c file with crafted inline assembly code.
No detection rules found.
No writeups or analysis indexed.
http://bugs.gentoo.org/show_bug.cgi?id=99464http://secunia.com/advisories/21508http://secunia.com/advisories/21530http://www.osvdb.org/27960http://www.securityfocus.com/bid/19555http://www.ubuntu.com/usn/usn-336-1http://www.vupen.com/english/advisories/2006/3307http://bugs.gentoo.org/show_bug.cgi?id=99464http://secunia.com/advisories/21508http://secunia.com/advisories/21530http://www.osvdb.org/27960http://www.securityfocus.com/bid/19555http://www.ubuntu.com/usn/usn-336-1http://www.vupen.com/english/advisories/2006/3307
2005-12-31
Published