cbcvebase.
CVE-2012-3509
published 2012-09-05

CVE-2012-3509: Multiple integer overflows in the (1) _objalloc_alloc function in objalloc.c and (2) objalloc_alloc macro in include/objalloc.h in GNU libiberty, as used by…

PriorityP426medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
3.63%
88.3th percentile
Multiple integer overflows in the (1) _objalloc_alloc function in objalloc.c and (2) objalloc_alloc macro in include/objalloc.h in GNU libiberty, as used by binutils 2.22, allow remote attackers to cause a denial of service (crash) via vectors related to the "addition of CHUNK_HEADER_SIZE to the length," which triggers a heap-based buffer overflow.

Affected

12 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debianbinutils< binutils 2.22-8 (bookworm)binutils 2.22-8 (bookworm)
debiandebian_linux
gnubinutils>= 0 < 2.22-82.22-8
gnubinutils>= 0 < 2.22-82.22-8
gnubinutils>= 0 < 2.22-82.22-8
gnubinutils>= 0 < 2.22-82.22-8
gnubinutils>= 0 < 2.24-5ubuntu3.12.24-5ubuntu3.1
gnubinutils>= 2.22 < 2.242.24

CVSS provenance

nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.