CVE-2014-8484
published 2014-12-09CVE-2014-8484: The srec_scan function in bfd/srec.c in libdbfd in GNU binutils before 2.25 allows remote attackers to cause a denial of service (out-of-bounds read) via a…
PriorityP426medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
5.08%
91.5th percentile
The srec_scan function in bfd/srec.c in libdbfd in GNU binutils before 2.25 allows remote attackers to cause a denial of service (out-of-bounds read) via a small S-record.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | binutils | < binutils 2.24.51.20140903-1 (bookworm) | binutils 2.24.51.20140903-1 (bookworm) |
| debian | binutils-mingw-w64 | < binutils 2.24.51.20140903-1 (bookworm) | binutils 2.24.51.20140903-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| gnu | binutils | <= 2.24 | — |
| gnu | binutils | >= 0 < 2.24.51.20140903-1 | 2.24.51.20140903-1 |
| gnu | binutils | >= 0 < 2.24.51.20140903-1 | 2.24.51.20140903-1 |
| gnu | binutils | >= 0 < 2.24.51.20140903-1 | 2.24.51.20140903-1 |
| gnu | binutils | >= 0 < 2.24.51.20140903-1 | 2.24.51.20140903-1 |
| gnu | binutils | >= 0 < 2.24-5ubuntu3.1 | 2.24-5ubuntu3.1 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4xrc-9849-6cr3: The srec_scan function in bfd/srec
ghsa_unreviewed·2022-05-17
CVE-2014-8484 [MEDIUM] CWE-119 GHSA-4xrc-9849-6cr3: The srec_scan function in bfd/srec
The srec_scan function in bfd/srec.c in libdbfd in GNU binutils before 2.25 allows remote attackers to cause a denial of service (out-of-bounds read) via a small S-record.
OSV
binutils vulnerabilities
osv·2015-02-09·CVSS 7.5
CVE-2014-8485 [HIGH] binutils vulnerabilities
binutils vulnerabilities
Michal Zalewski discovered that the setup_group function in libbfd in
GNU binutils did not properly check group headers in ELF files. An
attacker could use this to craft input that could cause a denial
of service (application crash) or possibly execute arbitrary code.
(CVE-2014-8485)
Hanno Böck discovered that the _bfd_XXi_swap_aouthdr_in function
in libbfd in GNU binutils allowed out-of-bounds writes. An
attacker could use this to craft input that could cause a denial
of service (application crash) or possibly execute arbitrary code.
(CVE-2014-8501)
Hanno Böck discovered a heap-based buffer overflow in the
pe_print_edata function in libbfd in GNU binutils. An attacker
could use this to craft input that could cause a denial of service
(application crash) or poss
OSV
CVE-2014-8484: The srec_scan function in bfd/srec
osv·2014-12-09·CVSS 5.0
CVE-2014-8484 [MEDIUM] CVE-2014-8484: The srec_scan function in bfd/srec
The srec_scan function in bfd/srec.c in libdbfd in GNU binutils before 2.25 allows remote attackers to cause a denial of service (out-of-bounds read) via a small S-record.
Ubuntu
GNU binutils vulnerabilities
vendor_ubuntu·2015-02-09·CVSS 7.5
CVE-2012-3509 [HIGH] GNU binutils vulnerabilities
Title: GNU binutils vulnerabilities
Summary: Applications from GNU binutils could be made to crash, run programs,
or delete arbitrary files as your login if they opened a specially
crafted file.
Michal Zalewski discovered that the setup_group function in libbfd in
GNU binutils did not properly check group headers in ELF files. An
attacker could use this to craft input that could cause a denial
of service (application crash) or possibly execute arbitrary code.
(CVE-2014-8485)
Hanno Böck discovered that the _bfd_XXi_swap_aouthdr_in function
in libbfd in GNU binutils allowed out-of-bounds writes. An
attacker could use this to craft input that could cause a denial
of service (application crash) or possibly execute arbitrary code.
(CVE-2014-8501)
Hanno Böck discovered a heap-based buffer ov
Red Hat
binutils: invalid read flaw in libbfd
vendor_redhat·2014-10-20·CVSS 5.0
CVE-2014-8484 [MEDIUM] CWE-839 binutils: invalid read flaw in libbfd
binutils: invalid read flaw in libbfd
The srec_scan function in bfd/srec.c in libdbfd in GNU binutils before 2.25 allows remote attackers to cause a denial of service (out-of-bounds read) via a small S-record.
An integer overflow flaw was found in the way the strings utility processed certain files. If a user were tricked into running the strings utility on a specially crafted file, it could cause the strings executable to crash.
Statement: Red Hat Enterprise Linux 5 is now in Production 3 Phase of the support and maintenance life cycle. This has been rated as having Moderate security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/
Debian
CVE-2014-8484: binutils - The srec_scan function in bfd/srec.c in libdbfd in GNU binutils before 2.25 allo...
vendor_debian·2014·CVSS 5.0
CVE-2014-8484 [MEDIUM] CVE-2014-8484: binutils - The srec_scan function in bfd/srec.c in libdbfd in GNU binutils before 2.25 allo...
The srec_scan function in bfd/srec.c in libdbfd in GNU binutils before 2.25 allows remote attackers to cause a denial of service (out-of-bounds read) via a small S-record.
Scope: local
bookworm: resolved (fixed in 2.24.51.20140903-1)
bullseye: resolved (fixed in 2.24.51.20140903-1)
forky: resolved (fixed in 2.24.51.20140903-1)
sid: resolved (fixed in 2.24.51.20140903-1)
trixie: resolved (fixed in 2.24.51.20140903-1)
No detection rules found.
No public exploits indexed.
http://lists.fedoraproject.org/pipermail/package-announce/2014-December/145262.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-December/145328.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-December/145742.htmlhttp://openwall.com/lists/oss-security/2014/10/23/5http://secunia.com/advisories/62241http://secunia.com/advisories/62746http://www.mandriva.com/security/advisories?name=MDVSA-2015:029http://www.openwall.com/lists/oss-security/2014/10/26/2http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/70714http://www.ubuntu.com/usn/USN-2496-1https://bugzilla.redhat.com/show_bug.cgi?id=1156272https://security.gentoo.org/glsa/201612-24https://sourceware.org/bugzilla/show_bug.cgi?id=17509https://sourceware.org/git/?p=binutils-gdb.git%3Ba=commit%3Bh=bd25671c6f202c4a5108883caa2adb24ff6f361fhttp://lists.fedoraproject.org/pipermail/package-announce/2014-December/145262.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-December/145328.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-December/145742.htmlhttp://openwall.com/lists/oss-security/2014/10/23/5http://secunia.com/advisories/62241http://secunia.com/advisories/62746http://www.mandriva.com/security/advisories?name=MDVSA-2015:029http://www.openwall.com/lists/oss-security/2014/10/26/2http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/70714http://www.ubuntu.com/usn/USN-2496-1https://bugzilla.redhat.com/show_bug.cgi?id=1156272https://security.gentoo.org/glsa/201612-24https://sourceware.org/bugzilla/show_bug.cgi?id=17509https://sourceware.org/git/?p=binutils-gdb.git%3Ba=commit%3Bh=bd25671c6f202c4a5108883caa2adb24ff6f361f
2014-12-09
Published