CVE-2006-2362
published 2006-05-15CVE-2006-2362: Buffer overflow in getsym in tekhex.c in libbfd in Free Software Foundation GNU Binutils before 20060423, as used by GNU strings, allows context-dependent…
PriorityP341high7.3CVSS 3.1
AVNACLPRNUINSUCLILAL
EXPLOIT
EPSS
14.49%
96.2th percentile
Buffer overflow in getsym in tekhex.c in libbfd in Free Software Foundation GNU Binutils before 20060423, as used by GNU strings, allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a file with a crafted Tektronix Hex Format (TekHex) record in which the length character is not a valid hexadecimal character.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | binutils | < binutils 2.17-1 (bookworm) | binutils 2.17-1 (bookworm) |
| gnu | binutils | < 2.17 | 2.17 |
| gnu | binutils | >= 0 < 2.17-1 | 2.17-1 |
| gnu | binutils | >= 0 < 2.17-1 | 2.17-1 |
| gnu | binutils | >= 0 < 2.17-1 | 2.17-1 |
| gnu | binutils | >= 0 < 2.17-1 | 2.17-1 |
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.3HIGH
vendor_debian7.3LOW
vendor_ubuntu7.3HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vrm3-57g8-gwv8: Buffer overflow in getsym in tekhex
ghsa_unreviewed·2022-05-01
CVE-2006-2362 [HIGH] CWE-787 GHSA-vrm3-57g8-gwv8: Buffer overflow in getsym in tekhex
Buffer overflow in getsym in tekhex.c in libbfd in Free Software Foundation GNU Binutils before 20060423, as used by GNU strings, allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a file with a crafted Tektronix Hex Format (TekHex) record in which the length character is not a valid hexadecimal character.
OSV
CVE-2006-2362: Buffer overflow in getsym in tekhex
osv·2006-05-15·CVSS 7.3
CVE-2006-2362 [HIGH] CVE-2006-2362: Buffer overflow in getsym in tekhex
Buffer overflow in getsym in tekhex.c in libbfd in Free Software Foundation GNU Binutils before 20060423, as used by GNU strings, allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a file with a crafted Tektronix Hex Format (TekHex) record in which the length character is not a valid hexadecimal character.
Ubuntu
binutils vulnerability
vendor_ubuntu·2006-06-09·CVSS 7.3
CVE-2006-2362 [HIGH] binutils vulnerability
Title: binutils vulnerability
Summary: binutils vulnerability
CVE-2006-2362
Jesus Olmos Gonzalez discovered a buffer overflow in the Tektronix Hex
Format (TekHex) backend of the BFD library, such as used by the
'strings' utility. By tricking an user or automated system into
processing a specially crafted file with 'strings' or a vulnerable
third-party application using the BFD library, this could be exploited
to crash the application, or possibly even execute arbitrary code with
the privileges of the user.
Instructions: In general, a standard system upgrade is sufficient to effect the
necessary changes.
Debian
CVE-2006-2362: binutils - Buffer overflow in getsym in tekhex.c in libbfd in Free Software Foundation GNU ...
vendor_debian·2006·CVSS 7.3
CVE-2006-2362 [HIGH] CVE-2006-2362: binutils - Buffer overflow in getsym in tekhex.c in libbfd in Free Software Foundation GNU ...
Buffer overflow in getsym in tekhex.c in libbfd in Free Software Foundation GNU Binutils before 20060423, as used by GNU strings, allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a file with a crafted Tektronix Hex Format (TekHex) record in which the length character is not a valid hexadecimal character.
Scope: local
bookworm: resolved (fixed in 2.17-1)
bullseye: resolved (fixed in 2.17-1)
forky: resolved (fixed in 2.17-1)
sid: resolved (fixed in 2.17-1)
trixie: resolved (fixed in 2.17-1)
No detection rules found.
No writeups or analysis indexed.
http://lists.apple.com/archives/security-announce/2007/Oct/msg00001.htmlhttp://secunia.com/advisories/20188http://secunia.com/advisories/20531http://secunia.com/advisories/20550http://secunia.com/advisories/22932http://secunia.com/advisories/27441http://sourceware.org/bugzilla/show_bug.cgi?id=2584http://www.mail-archive.com/bug-binutils%40gnu.org/msg01516.htmlhttp://www.novell.com/linux/security/advisories/2006_26_sr.htmlhttp://www.securityfocus.com/bid/17950http://www.securitytracker.com/id?1018872http://www.trustix.org/errata/2006/0034/http://www.ubuntu.com/usn/usn-292-1http://www.vupen.com/english/advisories/2006/1924http://www.vupen.com/english/advisories/2007/3665https://exchange.xforce.ibmcloud.com/vulnerabilities/26644http://lists.apple.com/archives/security-announce/2007/Oct/msg00001.htmlhttp://secunia.com/advisories/20188http://secunia.com/advisories/20531http://secunia.com/advisories/20550http://secunia.com/advisories/22932http://secunia.com/advisories/27441http://sourceware.org/bugzilla/show_bug.cgi?id=2584http://www.mail-archive.com/bug-binutils%40gnu.org/msg01516.htmlhttp://www.novell.com/linux/security/advisories/2006_26_sr.htmlhttp://www.securityfocus.com/bid/17950http://www.securitytracker.com/id?1018872http://www.trustix.org/errata/2006/0034/http://www.ubuntu.com/usn/usn-292-1http://www.vupen.com/english/advisories/2006/1924http://www.vupen.com/english/advisories/2007/3665https://exchange.xforce.ibmcloud.com/vulnerabilities/26644
2006-05-15
Published