CVE-2012-3509
published 2012-09-05CVE-2012-3509: Multiple integer overflows in the (1) _objalloc_alloc function in objalloc.c and (2) objalloc_alloc macro in include/objalloc.h in GNU libiberty, as used by…
PriorityP426medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
3.63%
88.3th percentile
Multiple integer overflows in the (1) _objalloc_alloc function in objalloc.c and (2) objalloc_alloc macro in include/objalloc.h in GNU libiberty, as used by binutils 2.22, allow remote attackers to cause a denial of service (crash) via vectors related to the "addition of CHUNK_HEADER_SIZE to the length," which triggers a heap-based buffer overflow.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | binutils | < binutils 2.22-8 (bookworm) | binutils 2.22-8 (bookworm) |
| debian | debian_linux | — | — |
| gnu | binutils | >= 0 < 2.22-8 | 2.22-8 |
| gnu | binutils | >= 0 < 2.22-8 | 2.22-8 |
| gnu | binutils | >= 0 < 2.22-8 | 2.22-8 |
| gnu | binutils | >= 0 < 2.22-8 | 2.22-8 |
| gnu | binutils | >= 0 < 2.24-5ubuntu3.1 | 2.24-5ubuntu3.1 |
| gnu | binutils | >= 2.22 < 2.24 | 2.24 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
GNU binutils vulnerabilities
vendor_ubuntu·2015-02-09·CVSS 7.5
CVE-2012-3509 [HIGH] GNU binutils vulnerabilities
Title: GNU binutils vulnerabilities
Summary: Applications from GNU binutils could be made to crash, run programs,
or delete arbitrary files as your login if they opened a specially
crafted file.
Michal Zalewski discovered that the setup_group function in libbfd in
GNU binutils did not properly check group headers in ELF files. An
attacker could use this to craft input that could cause a denial
of service (application crash) or possibly execute arbitrary code.
(CVE-2014-8485)
Hanno Böck discovered that the _bfd_XXi_swap_aouthdr_in function
in libbfd in GNU binutils allowed out-of-bounds writes. An
attacker could use this to craft input that could cause a denial
of service (application crash) or possibly execute arbitrary code.
(CVE-2014-8501)
Hanno Böck discovered a heap-based buffer ov
Red Hat
libiberty: integer overflow, leading to heap-buffer overflow by processing certain file headers via bfd binary
vendor_redhat·2012-08-29·CVSS 5.0
CVE-2012-3509 [MEDIUM] CWE-190 libiberty: integer overflow, leading to heap-buffer overflow by processing certain file headers via bfd binary
libiberty: integer overflow, leading to heap-buffer overflow by processing certain file headers via bfd binary
Multiple integer overflows in the (1) _objalloc_alloc function in objalloc.c and (2) objalloc_alloc macro in include/objalloc.h in GNU libiberty, as used by binutils 2.22, allow remote attackers to cause a denial of service (crash) via vectors related to the "addition of CHUNK_HEADER_SIZE to the length," which triggers a heap-based buffer overflow.
Statement: The versions of the gdb package, as shipped with Red Hat Enterprise Linux 5 and 6 are vulnerable to the original libiberty integer overflow flaw. But due the way of subsequent processing of the previously insufficiently pre-allocated libiberty buffer within gdb code, the impact of this issue is limited to crash only. Red Ha
Debian
CVE-2012-3509: binutils - Multiple integer overflows in the (1) _objalloc_alloc function in objalloc.c and...
vendor_debian·2012·CVSS 5.0
CVE-2012-3509 [MEDIUM] CVE-2012-3509: binutils - Multiple integer overflows in the (1) _objalloc_alloc function in objalloc.c and...
Multiple integer overflows in the (1) _objalloc_alloc function in objalloc.c and (2) objalloc_alloc macro in include/objalloc.h in GNU libiberty, as used by binutils 2.22, allow remote attackers to cause a denial of service (crash) via vectors related to the "addition of CHUNK_HEADER_SIZE to the length," which triggers a heap-based buffer overflow.
Scope: local
bookworm: resolved (fixed in 2.22-8)
bullseye: resolved (fixed in 2.22-8)
forky: resolved (fixed in 2.22-8)
sid: resolved (fixed in 2.22-8)
trixie: resolved (fixed in 2.22-8)
GHSA
GHSA-pjv6-3frr-mr92: Multiple integer overflows in the (1) _objalloc_alloc function in objalloc
ghsa_unreviewed·2022-05-17
CVE-2012-3509 [MEDIUM] GHSA-pjv6-3frr-mr92: Multiple integer overflows in the (1) _objalloc_alloc function in objalloc
Multiple integer overflows in the (1) _objalloc_alloc function in objalloc.c and (2) objalloc_alloc macro in include/objalloc.h in GNU libiberty, as used by binutils 2.22, allow remote attackers to cause a denial of service (crash) via vectors related to the "addition of CHUNK_HEADER_SIZE to the length," which triggers a heap-based buffer overflow.
OSV
binutils vulnerabilities
osv·2015-02-09·CVSS 7.5
CVE-2014-8485 [HIGH] binutils vulnerabilities
binutils vulnerabilities
Michal Zalewski discovered that the setup_group function in libbfd in
GNU binutils did not properly check group headers in ELF files. An
attacker could use this to craft input that could cause a denial
of service (application crash) or possibly execute arbitrary code.
(CVE-2014-8485)
Hanno Böck discovered that the _bfd_XXi_swap_aouthdr_in function
in libbfd in GNU binutils allowed out-of-bounds writes. An
attacker could use this to craft input that could cause a denial
of service (application crash) or possibly execute arbitrary code.
(CVE-2014-8501)
Hanno Böck discovered a heap-based buffer overflow in the
pe_print_edata function in libbfd in GNU binutils. An attacker
could use this to craft input that could cause a denial of service
(application crash) or poss
OSV
CVE-2012-3509: Multiple integer overflows in the (1) _objalloc_alloc function in objalloc
osv·2012-09-05·CVSS 5.0
CVE-2012-3509 [MEDIUM] CVE-2012-3509: Multiple integer overflows in the (1) _objalloc_alloc function in objalloc
Multiple integer overflows in the (1) _objalloc_alloc function in objalloc.c and (2) objalloc_alloc macro in include/objalloc.h in GNU libiberty, as used by binutils 2.22, allow remote attackers to cause a denial of service (crash) via vectors related to the "addition of CHUNK_HEADER_SIZE to the length," which triggers a heap-based buffer overflow.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-3509 insight: in bundled libiberty [fedora-rawhide]
bugzilla·2012-11-15·CVSS 5.0
CVE-2012-3509 [MEDIUM] CVE-2012-3509 insight: in bundled libiberty [fedora-rawhide]
CVE-2012-3509 insight: in bundled libiberty [fedora-rawhide]
This package bundles libiberty, and may need to be patched based on the patch referenced in 860769.
Discussion:
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=849693,877014
---
insight-7.4.50-4.20120403cvs.
Bugzilla
CVE-2012-3509 mono-debugger: in bundled libiberty [fedora-rawhide]
bugzilla·2012-11-15·CVSS 5.0
CVE-2012-3509 [MEDIUM] CVE-2012-3509 mono-debugger: in bundled libiberty [fedora-rawhide]
CVE-2012-3509 mono-debugger: in bundled libiberty [fedora-rawhide]
This package bundles libiberty, and may need to be patched based on the patch referenced in 860769.
Discussion:
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=849693,877017
---
This bug appears to hav
Bugzilla
CVE-2012-3509 mutrace: in bundled libiberty [fedora-rawhide]
bugzilla·2012-11-15·CVSS 5.0
CVE-2012-3509 [MEDIUM] CVE-2012-3509 mutrace: in bundled libiberty [fedora-rawhide]
CVE-2012-3509 mutrace: in bundled libiberty [fedora-rawhide]
This package bundles libiberty, and may need to be patched based on the patch referenced in 860769.
Discussion:
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=849693,877018
---
Hmm? mutrace does not use nor
Bugzilla
CVE-2012-3509 binutils: in bundled libiberty [fedora-rawhide]
bugzilla·2012-11-15·CVSS 5.0
CVE-2012-3509 [MEDIUM] CVE-2012-3509 binutils: in bundled libiberty [fedora-rawhide]
CVE-2012-3509 binutils: in bundled libiberty [fedora-rawhide]
This package bundles libiberty, and may need to be patched based on the patch referenced in 860769.
Discussion:
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=849693,877012
---
This bug appears to have bee
Bugzilla
CVE-2012-3509 libiberty: integer overflow, leading to heap-buffer overflow by processing certain file headers via bfd binary [fedora-all]
bugzilla·2012-09-26·CVSS 5.0
CVE-2012-3509 [MEDIUM] CVE-2012-3509 libiberty: integer overflow, leading to heap-buffer overflow by processing certain file headers via bfd binary [fedora-all]
CVE-2012-3509 libiberty: integer overflow, leading to heap-buffer overflow by processing certain file headers via bfd binary [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission lin
Bugzilla
CVE-2012-3509 libiberty: integer overflow, leading to heap-buffer overflow by processing certain file headers via bfd binary
bugzilla·2012-08-20·CVSS 5.0
CVE-2012-3509 [MEDIUM] CVE-2012-3509 libiberty: integer overflow, leading to heap-buffer overflow by processing certain file headers via bfd binary
CVE-2012-3509 libiberty: integer overflow, leading to heap-buffer overflow by processing certain file headers via bfd binary
An integer overflow, leading to heap-based buffer overflow flaw was found in the way libiberty library, a collection of subroutines used by various GNU programs, performed space allocation from an objalloc structure. A remote attacker could provide a binary file which specially-crafted header that, when processed by some of the bfd binaries (nm, objcopy, objdump etc.) would lead to that bfd executable crash or, potentially, arbitrary code execution with the privileges of the user running the bfd binary.
Discussion:
Is there a remote code execution possibility? (I do not think so.)
If we should fix all DoS (crash) problems it opens a whole new class of bugs (such
http://gcc.gnu.org/bugzilla/show_bug.cgi?id=54411http://gcc.gnu.org/ml/gcc-patches/2012-08/msg01986.htmlhttp://security-tracker.debian.org/tracker/CVE-2012-3509http://www.mandriva.com/security/advisories?name=MDVSA-2015:029http://www.openwall.com/lists/oss-security/2012/08/29/3http://www.securityfocus.com/bid/55281http://www.ubuntu.com/usn/USN-2496-1https://exchange.xforce.ibmcloud.com/vulnerabilities/78135http://gcc.gnu.org/bugzilla/show_bug.cgi?id=54411http://gcc.gnu.org/ml/gcc-patches/2012-08/msg01986.htmlhttp://security-tracker.debian.org/tracker/CVE-2012-3509http://www.mandriva.com/security/advisories?name=MDVSA-2015:029http://www.openwall.com/lists/oss-security/2012/08/29/3http://www.securityfocus.com/bid/55281http://www.ubuntu.com/usn/USN-2496-1https://exchange.xforce.ibmcloud.com/vulnerabilities/78135
2012-09-05
Published