CVE-2014-8485
published 2014-12-09CVE-2014-8485: The setup_group function in bfd/elf.c in libbfd in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly…
PriorityP344high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
7.49%
93.8th percentile
The setup_group function in bfd/elf.c in libbfd in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted section group headers in an ELF file.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | binutils | < binutils 2.24.90.20141104-1 (bookworm) | binutils 2.24.90.20141104-1 (bookworm) |
| debian | binutils-mingw-w64 | < binutils 2.24.90.20141104-1 (bookworm) | binutils 2.24.90.20141104-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| gnu | binutils | <= 2.24 | — |
| gnu | binutils | >= 0 < 2.24.90.20141104-1 | 2.24.90.20141104-1 |
| gnu | binutils | >= 0 < 2.24.90.20141104-1 | 2.24.90.20141104-1 |
| gnu | binutils | >= 0 < 2.24.90.20141104-1 | 2.24.90.20141104-1 |
| gnu | binutils | >= 0 < 2.24.90.20141104-1 | 2.24.90.20141104-1 |
| gnu | binutils | >= 0 < 2.24-5ubuntu3.1 | 2.24-5ubuntu3.1 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-67h2-mpm8-hmxf: The setup_group function in bfd/elf
ghsa_unreviewed·2022-05-17
CVE-2014-8485 [HIGH] CWE-94 GHSA-67h2-mpm8-hmxf: The setup_group function in bfd/elf
The setup_group function in bfd/elf.c in libbfd in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted section group headers in an ELF file.
OSV
binutils vulnerabilities
osv·2015-02-09·CVSS 7.5
CVE-2014-8485 [HIGH] binutils vulnerabilities
binutils vulnerabilities
Michal Zalewski discovered that the setup_group function in libbfd in
GNU binutils did not properly check group headers in ELF files. An
attacker could use this to craft input that could cause a denial
of service (application crash) or possibly execute arbitrary code.
(CVE-2014-8485)
Hanno Böck discovered that the _bfd_XXi_swap_aouthdr_in function
in libbfd in GNU binutils allowed out-of-bounds writes. An
attacker could use this to craft input that could cause a denial
of service (application crash) or possibly execute arbitrary code.
(CVE-2014-8501)
Hanno Böck discovered a heap-based buffer overflow in the
pe_print_edata function in libbfd in GNU binutils. An attacker
could use this to craft input that could cause a denial of service
(application crash) or poss
OSV
CVE-2014-8485: The setup_group function in bfd/elf
osv·2014-12-09·CVSS 7.5
CVE-2014-8485 [HIGH] CVE-2014-8485: The setup_group function in bfd/elf
The setup_group function in bfd/elf.c in libbfd in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted section group headers in an ELF file.
Ubuntu
GNU binutils vulnerabilities
vendor_ubuntu·2015-02-09·CVSS 7.5
CVE-2012-3509 [HIGH] GNU binutils vulnerabilities
Title: GNU binutils vulnerabilities
Summary: Applications from GNU binutils could be made to crash, run programs,
or delete arbitrary files as your login if they opened a specially
crafted file.
Michal Zalewski discovered that the setup_group function in libbfd in
GNU binutils did not properly check group headers in ELF files. An
attacker could use this to craft input that could cause a denial
of service (application crash) or possibly execute arbitrary code.
(CVE-2014-8485)
Hanno Böck discovered that the _bfd_XXi_swap_aouthdr_in function
in libbfd in GNU binutils allowed out-of-bounds writes. An
attacker could use this to craft input that could cause a denial
of service (application crash) or possibly execute arbitrary code.
(CVE-2014-8501)
Hanno Böck discovered a heap-based buffer ov
Red Hat
binutils: heap overflow in objdump when parsing a crafted ELF/PE binary file (incomplete fix for CVE-2014-8485)
vendor_redhat·2014-10-28·CVSS 7.5
CVE-2014-8502 [HIGH] CWE-122 binutils: heap overflow in objdump when parsing a crafted ELF/PE binary file (incomplete fix for CVE-2014-8485)
binutils: heap overflow in objdump when parsing a crafted ELF/PE binary file (incomplete fix for CVE-2014-8485)
Heap-based buffer overflow in the pe_print_edata function in bfd/peXXigen.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly have other unspecified impact via a truncated export table in a PE file.
It was found that the fix for the CVE-2014-8485 issue was incomplete: a heap-based buffer overflow in the objdump utility could cause it to crash or, potentially, execute arbitrary code with the privileges of the user running objdump when processing specially crafted files.
Statement: Red Hat Enterprise Linux 5 is now in Production 3 Phase of the support and maintenance life cycle. This has been rated as having Low security i
Red Hat
binutils: lack of range checking leading to controlled write in _bfd_elf_setup_sections()
vendor_redhat·2014-10-24·CVSS 7.5
CVE-2014-8485 [HIGH] CWE-822 binutils: lack of range checking leading to controlled write in _bfd_elf_setup_sections()
binutils: lack of range checking leading to controlled write in _bfd_elf_setup_sections()
The setup_group function in bfd/elf.c in libbfd in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted section group headers in an ELF file.
A buffer overflow flaw was found in the way various binutils utilities processed certain files. If a user were tricked into processing a specially crafted file, it could cause the utility used to process that file to crash or, potentially, execute arbitrary code with the privileges of the user running that utility.
Statement: Red Hat Enterprise Linux 5 is now in Production 3 Phase of the support and maintenance life cycle. This has been rated as having Moderate security impa
Debian
CVE-2014-8485: binutils - The setup_group function in bfd/elf.c in libbfd in GNU binutils 2.24 and earlier...
vendor_debian·2014·CVSS 7.5
CVE-2014-8485 [HIGH] CVE-2014-8485: binutils - The setup_group function in bfd/elf.c in libbfd in GNU binutils 2.24 and earlier...
The setup_group function in bfd/elf.c in libbfd in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted section group headers in an ELF file.
Scope: local
bookworm: resolved (fixed in 2.24.90.20141104-1)
bullseye: resolved (fixed in 2.24.90.20141104-1)
forky: resolved (fixed in 2.24.90.20141104-1)
sid: resolved (fixed in 2.24.90.20141104-1)
trixie: resolved (fixed in 2.24.90.20141104-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-8502 binutils: heap overflow in objdump when parsing a crafted ELF/PE binary file (incomplete fix for CVE-2014-8485)
bugzilla·2014-11-11·CVSS 7.5
CVE-2014-8502 [HIGH] CVE-2014-8502 binutils: heap overflow in objdump when parsing a crafted ELF/PE binary file (incomplete fix for CVE-2014-8485)
CVE-2014-8502 binutils: heap overflow in objdump when parsing a crafted ELF/PE binary file (incomplete fix for CVE-2014-8485)
A heap overflow was reborted [1] when running objdump on a specially crafted PE executable [2].
Upstream patches that address this are at [3] and [4].
[1]: https://sourceware.org/bugzilla/show_bug.cgi?id=17512#c17
[2]: https://sourceware.org/bugzilla/attachment.cgi?id=7862
[3]: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=5a4b0ccc20ba30caef53b01bee2c0aaa5b855339
[4]: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=acafeb6056bec47d7211cf462a7c211a8c95cf42
Discussion:
Created mingw-binutils tracking bugs for this issue:
Affects: fedora-all [bug 1162602]
Affects: epel-all [bug 1162606]
---
Created avr-binutils tracking bugs for this issu
Bugzilla
CVE-2014-8485 binutils: lack of range checking leading to controlled write in _bfd_elf_setup_sections()
bugzilla·2014-10-26·CVSS 7.5
CVE-2014-8485 [HIGH] CVE-2014-8485 binutils: lack of range checking leading to controlled write in _bfd_elf_setup_sections()
CVE-2014-8485 binutils: lack of range checking leading to controlled write in _bfd_elf_setup_sections()
Michal Zalewski reported a lack of range checking in libbfd could be used to write to an arbitrary location in memory:
http://lcamtuf.blogspot.co.uk/2014/10/psa-dont-run-strings-on-untrusted-files.html
Running "strings" on a malicious file could cause "strings" to crash or, potentially, execute arbitrary code.
Upstream bug (no patch attached yet):
https://sourceware.org/bugzilla/show_bug.cgi?id=17510
References:
http://www.openwall.com/lists/oss-security/2014/10/24/10
Discussion:
Created binutils tracking bugs for this issue:
Affects: fedora-all [bug 1157277]
---
As noted in , other utilities which are commonly run on untrusted binaries are also affected, such as objdump and
Bugzilla
CVE-2014-8484 binutils: invalid read flaw in libbfd
bugzilla·2014-10-24·CVSS 5.0
CVE-2014-8484 [MEDIUM] CVE-2014-8484 binutils: invalid read flaw in libbfd
CVE-2014-8484 binutils: invalid read flaw in libbfd
Michal Zalewski reported an invalid read flaw in libbfd, used by, for example, the "strings" utility. Running "strings" on a malicious file could cause "strings" to crash:
http://seclists.org/oss-sec/2014/q4/424
It is unclear yet if it is possible to leverage this issue for more than a crash.
Dave Rutherford noted on oss-security that using certain web browsers to save a malicious file could trigger this issue and cause the browser to crash:
http://seclists.org/oss-sec/2014/q4/426
Discussion:
I haven't looked deeply at this, but if the problem is truely in the srec code rather than higher up in the call chain, then I'd consider this pretty low priority. srecords aren't really used anymore and one could easily argue they should not
http://lcamtuf.blogspot.co.uk/2014/10/psa-dont-run-strings-on-untrusted-files.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-December/145262.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-December/145328.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-December/145742.htmlhttp://secunia.com/advisories/62241http://secunia.com/advisories/62746http://www.mandriva.com/security/advisories?name=MDVSA-2015:029http://www.openwall.com/lists/oss-security/2014/10/26/2http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/70741http://www.ubuntu.com/usn/USN-2496-1https://bugzilla.redhat.com/show_bug.cgi?id=1157276https://security.gentoo.org/glsa/201612-24https://sourceware.org/bugzilla/show_bug.cgi?id=17510https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git%3Ba=commit%3Bh=493a33860c71cac998f1a56d6d87d6faa801fbaahttp://lcamtuf.blogspot.co.uk/2014/10/psa-dont-run-strings-on-untrusted-files.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-December/145262.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-December/145328.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-December/145742.htmlhttp://secunia.com/advisories/62241http://secunia.com/advisories/62746http://www.mandriva.com/security/advisories?name=MDVSA-2015:029http://www.openwall.com/lists/oss-security/2014/10/26/2http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/70741http://www.ubuntu.com/usn/USN-2496-1https://bugzilla.redhat.com/show_bug.cgi?id=1157276https://security.gentoo.org/glsa/201612-24https://sourceware.org/bugzilla/show_bug.cgi?id=17510https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git%3Ba=commit%3Bh=493a33860c71cac998f1a56d6d87d6faa801fbaa
2014-12-09
Published