Severity
7.5HIGHNVD
EPSS
4.2%
top 11.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 9
Latest updateMay 17

Description

The setup_group function in bfd/elf.c in libbfd in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted section group headers in an ELF file.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages3 packages

Debiangnu/binutils< 2.24.90.20141104-1+3
Ubuntugnu/binutils< 2.24-5ubuntu3.1
NVDgnu/binutils2.24

Also affects: Fedora 19, 20, 21, Ubuntu Linux 10.04, 12.04, 14.04, 14.10

🔴Vulnerability Details

4
GHSA
GHSA-67h2-mpm8-hmxf: The setup_group function in bfd/elf2022-05-17
OSV
binutils vulnerabilities2015-02-09
CVEList
CVE-2014-8485: The setup_group function in bfd/elf2014-12-09
OSV
CVE-2014-8485: The setup_group function in bfd/elf2014-12-09

📋Vendor Advisories

4
Ubuntu
GNU binutils vulnerabilities2015-02-09
Red Hat
binutils: heap overflow in objdump when parsing a crafted ELF/PE binary file (incomplete fix for CVE-2014-8485)2014-10-28
Red Hat
binutils: lack of range checking leading to controlled write in _bfd_elf_setup_sections()2014-10-24
Debian
CVE-2014-8485: binutils - The setup_group function in bfd/elf.c in libbfd in GNU binutils 2.24 and earlier...2014

💬Community

2
Bugzilla
CVE-2014-8502 binutils: heap overflow in objdump when parsing a crafted ELF/PE binary file (incomplete fix for CVE-2014-8485)2014-11-11
Bugzilla
CVE-2014-8485 binutils: lack of range checking leading to controlled write in _bfd_elf_setup_sections()2014-10-26
CVE-2014-8485 — Code Injection in GNU Binutils | cvebase