CVE-2014-8501
published 2014-12-09CVE-2014-8501: The _bfd_XXi_swap_aouthdr_in function in bfd/peXXigen.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (out-of-bounds…
PriorityP336high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
5.16%
91.5th percentile
The _bfd_XXi_swap_aouthdr_in function in bfd/peXXigen.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (out-of-bounds write) and possibly have other unspecified impact via a crafted NumberOfRvaAndSizes field in the AOUT header in a PE executable.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | binutils | < binutils 2.24.90.20141104-1 (bookworm) | binutils 2.24.90.20141104-1 (bookworm) |
| debian | binutils-mingw-w64 | < binutils 2.24.90.20141104-1 (bookworm) | binutils 2.24.90.20141104-1 (bookworm) |
| debian | gdb | < binutils 2.24.90.20141104-1 (bookworm) | binutils 2.24.90.20141104-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| gnu | binutils | <= 2.24 | — |
| gnu | binutils | >= 0 < 2.24.90.20141104-1 | 2.24.90.20141104-1 |
| gnu | binutils | >= 0 < 2.24.90.20141104-1 | 2.24.90.20141104-1 |
| gnu | binutils | >= 0 < 2.24.90.20141104-1 | 2.24.90.20141104-1 |
| gnu | binutils | >= 0 < 2.24.90.20141104-1 | 2.24.90.20141104-1 |
| gnu | binutils | >= 0 < 2.24-5ubuntu3.1 | 2.24-5ubuntu3.1 |
| gnu | gdb | >= 0 < 7.7.1-0ubuntu5~14.04.3 | 7.7.1-0ubuntu5~14.04.3 |
| gnu | gdb | >= 0 < 7.11.1-0ubuntu1~16.5 | 7.11.1-0ubuntu1~16.5 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qfpv-68g4-gwwq: The _bfd_XXi_swap_aouthdr_in function in bfd/peXXigen
ghsa_unreviewed·2022-05-17
CVE-2014-8501 [HIGH] CWE-119 GHSA-qfpv-68g4-gwwq: The _bfd_XXi_swap_aouthdr_in function in bfd/peXXigen
The _bfd_XXi_swap_aouthdr_in function in bfd/peXXigen.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (out-of-bounds write) and possibly have other unspecified impact via a crafted NumberOfRvaAndSizes field in the AOUT header in a PE executable.
OSV
gdb vulnerabilities
osv·2017-07-26·CVSS 7.5
CVE-2014-8501 [HIGH] gdb vulnerabilities
gdb vulnerabilities
Hanno Böck discovered that gdb incorrectly handled certain malformed AOUT
headers in PE executables. If a user or automated system were tricked into
processing a specially crafted binary, a remote attacker could use this
issue to cause gdb to crash, resulting in a denial of service, or possibly
execute arbitrary code. This issue only applied to Ubuntu 14.04 LTS.
(CVE-2014-8501)
It was discovered that gdb incorrectly handled printing bad bytes in Intel
Hex objects. If a user or automated system were tricked into processing a
specially crafted binary, a remote attacker could use this issue to cause
gdb to crash, resulting in a denial of service. This issue only applied to
Ubuntu 14.04 LTS. (CVE-2014-9939)
It was discovered that gdb incorrectly handled certain string op
OSV
binutils vulnerabilities
osv·2015-02-09·CVSS 7.5
CVE-2014-8485 [HIGH] binutils vulnerabilities
binutils vulnerabilities
Michal Zalewski discovered that the setup_group function in libbfd in
GNU binutils did not properly check group headers in ELF files. An
attacker could use this to craft input that could cause a denial
of service (application crash) or possibly execute arbitrary code.
(CVE-2014-8485)
Hanno Böck discovered that the _bfd_XXi_swap_aouthdr_in function
in libbfd in GNU binutils allowed out-of-bounds writes. An
attacker could use this to craft input that could cause a denial
of service (application crash) or possibly execute arbitrary code.
(CVE-2014-8501)
Hanno Böck discovered a heap-based buffer overflow in the
pe_print_edata function in libbfd in GNU binutils. An attacker
could use this to craft input that could cause a denial of service
(application crash) or poss
OSV
CVE-2014-8501: The _bfd_XXi_swap_aouthdr_in function in bfd/peXXigen
osv·2014-12-09·CVSS 7.5
CVE-2014-8501 [HIGH] CVE-2014-8501: The _bfd_XXi_swap_aouthdr_in function in bfd/peXXigen
The _bfd_XXi_swap_aouthdr_in function in bfd/peXXigen.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (out-of-bounds write) and possibly have other unspecified impact via a crafted NumberOfRvaAndSizes field in the AOUT header in a PE executable.
Ubuntu
gdb vulnerabilities
vendor_ubuntu·2017-07-26·CVSS 7.5
CVE-2014-8501 [HIGH] gdb vulnerabilities
Title: gdb vulnerabilities
Summary: Several security issues were fixed in gdb.
Hanno Böck discovered that gdb incorrectly handled certain malformed AOUT
headers in PE executables. If a user or automated system were tricked into
processing a specially crafted binary, a remote attacker could use this
issue to cause gdb to crash, resulting in a denial of service, or possibly
execute arbitrary code. This issue only applied to Ubuntu 14.04 LTS.
(CVE-2014-8501)
It was discovered that gdb incorrectly handled printing bad bytes in Intel
Hex objects. If a user or automated system were tricked into processing a
specially crafted binary, a remote attacker could use this issue to cause
gdb to crash, resulting in a denial of service. This issue only applied to
Ubuntu 14.04 LTS. (CVE-2014-9939)
It w
Ubuntu
GNU binutils vulnerabilities
vendor_ubuntu·2015-02-09·CVSS 7.5
CVE-2012-3509 [HIGH] GNU binutils vulnerabilities
Title: GNU binutils vulnerabilities
Summary: Applications from GNU binutils could be made to crash, run programs,
or delete arbitrary files as your login if they opened a specially
crafted file.
Michal Zalewski discovered that the setup_group function in libbfd in
GNU binutils did not properly check group headers in ELF files. An
attacker could use this to craft input that could cause a denial
of service (application crash) or possibly execute arbitrary code.
(CVE-2014-8485)
Hanno Böck discovered that the _bfd_XXi_swap_aouthdr_in function
in libbfd in GNU binutils allowed out-of-bounds writes. An
attacker could use this to craft input that could cause a denial
of service (application crash) or possibly execute arbitrary code.
(CVE-2014-8501)
Hanno Böck discovered a heap-based buffer ov
Red Hat
binutils: out-of-bounds write when parsing specially crafted PE executable
vendor_redhat·2014-10-26·CVSS 7.5
CVE-2014-8501 [HIGH] CWE-787 binutils: out-of-bounds write when parsing specially crafted PE executable
binutils: out-of-bounds write when parsing specially crafted PE executable
The _bfd_XXi_swap_aouthdr_in function in bfd/peXXigen.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (out-of-bounds write) and possibly have other unspecified impact via a crafted NumberOfRvaAndSizes field in the AOUT header in a PE executable.
A stack-based buffer overflow flaw was found in the way various binutils utilities processed certain files. If a user were tricked into processing a specially crafted file, it could cause the utility used to process that file to crash or, potentially, execute arbitrary code with the privileges of the user running that utility.
Statement: Red Hat Enterprise Linux 5 is now in Production 3 Phase of the support and maintenance life cycl
Debian
CVE-2014-8501: binutils - The _bfd_XXi_swap_aouthdr_in function in bfd/peXXigen.c in GNU binutils 2.24 and...
vendor_debian·2014·CVSS 7.5
CVE-2014-8501 [HIGH] CVE-2014-8501: binutils - The _bfd_XXi_swap_aouthdr_in function in bfd/peXXigen.c in GNU binutils 2.24 and...
The _bfd_XXi_swap_aouthdr_in function in bfd/peXXigen.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (out-of-bounds write) and possibly have other unspecified impact via a crafted NumberOfRvaAndSizes field in the AOUT header in a PE executable.
Scope: local
bookworm: resolved (fixed in 2.24.90.20141104-1)
bullseye: resolved (fixed in 2.24.90.20141104-1)
forky: resolved (fixed in 2.24.90.20141104-1)
sid: resolved (fixed in 2.24.90.20141104-1)
trixie: resolved (fixed in 2.24.90.20141104-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-8501 msp430-binutils: binutils: out-of-bounds write when parsing specially crafted PE executable [fedora-all]
bugzilla·2014-11-11·CVSS 7.5
CVE-2014-8501 [HIGH] CVE-2014-8501 msp430-binutils: binutils: out-of-bounds write when parsing specially crafted PE executable [fedora-all]
CVE-2014-8501 msp430-binutils: binutils: out-of-bounds write when parsing specially crafted PE executable [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issu
Bugzilla
CVE-2014-8501 cross-binutils: binutils: out-of-bounds write when parsing specially crafted PE executable [epel-all]
bugzilla·2014-11-11·CVSS 7.5
CVE-2014-8501 [HIGH] CVE-2014-8501 cross-binutils: binutils: out-of-bounds write when parsing specially crafted PE executable [epel-all]
CVE-2014-8501 cross-binutils: binutils: out-of-bounds write when parsing specially crafted PE executable [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this is
Bugzilla
CVE-2014-8501 cross-binutils: binutils: out-of-bounds write when parsing specially crafted PE executable [fedora-all]
bugzilla·2014-11-11·CVSS 7.5
CVE-2014-8501 [HIGH] CVE-2014-8501 cross-binutils: binutils: out-of-bounds write when parsing specially crafted PE executable [fedora-all]
CVE-2014-8501 cross-binutils: binutils: out-of-bounds write when parsing specially crafted PE executable [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue
Bugzilla
CVE-2014-8501 binutils: out-of-bounds write when parsing specially crafted PE executable [fedora-all]
bugzilla·2014-11-11·CVSS 7.5
CVE-2014-8501 [HIGH] CVE-2014-8501 binutils: out-of-bounds write when parsing specially crafted PE executable [fedora-all]
CVE-2014-8501 binutils: out-of-bounds write when parsing specially crafted PE executable [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multipl
Bugzilla
CVE-2014-8501 mingw-binutils: binutils: out-of-bounds write when parsing specially crafted PE executable [epel-all]
bugzilla·2014-11-11·CVSS 7.5
CVE-2014-8501 [HIGH] CVE-2014-8501 mingw-binutils: binutils: out-of-bounds write when parsing specially crafted PE executable [epel-all]
CVE-2014-8501 mingw-binutils: binutils: out-of-bounds write when parsing specially crafted PE executable [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this is
Bugzilla
CVE-2014-8501 avr-binutils: binutils: out-of-bounds write when parsing specially crafted PE executable [fedora-all]
bugzilla·2014-11-11·CVSS 7.5
CVE-2014-8501 [HIGH] CVE-2014-8501 avr-binutils: binutils: out-of-bounds write when parsing specially crafted PE executable [fedora-all]
CVE-2014-8501 avr-binutils: binutils: out-of-bounds write when parsing specially crafted PE executable [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue a
Bugzilla
CVE-2014-8501 arm-none-eabi-binutils-cs: binutils: out-of-bounds write when parsing specially crafted PE executable [fedora-all]
bugzilla·2014-11-11·CVSS 7.5
CVE-2014-8501 [HIGH] CVE-2014-8501 arm-none-eabi-binutils-cs: binutils: out-of-bounds write when parsing specially crafted PE executable [fedora-all]
CVE-2014-8501 arm-none-eabi-binutils-cs: binutils: out-of-bounds write when parsing specially crafted PE executable [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE:
Bugzilla
CVE-2014-8501 avr-binutils: binutils: out-of-bounds write when parsing specially crafted PE executable [epel-all]
bugzilla·2014-11-11·CVSS 7.5
CVE-2014-8501 [HIGH] CVE-2014-8501 avr-binutils: binutils: out-of-bounds write when parsing specially crafted PE executable [epel-all]
CVE-2014-8501 avr-binutils: binutils: out-of-bounds write when parsing specially crafted PE executable [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issu
Bugzilla
CVE-2014-8501 binutils: out-of-bounds write when parsing specially crafted PE executable
bugzilla·2014-11-11·CVSS 7.5
CVE-2014-8501 [HIGH] CVE-2014-8501 binutils: out-of-bounds write when parsing specially crafted PE executable
CVE-2014-8501 binutils: out-of-bounds write when parsing specially crafted PE executable
It was reported [1] that running strings, nm or objdump on a constructed PE file [2] leads to out-of bounds write to an unitialized memory area.
Upstream path for this issue is at [3].
[1]: https://sourceware.org/bugzilla/show_bug.cgi?id=17512#c0
[2]: https://sourceware.org/bugzilla/attachment.cgi?id=7849
[3]: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=7e1e19887abd24aeb15066b141cdff5541e0ec8e
Discussion:
Created mingw-binutils tracking bugs for this issue:
Affects: fedora-all [bug 1162578]
Affects: epel-all [bug 1162583]
---
Created avr-binutils tracking bugs for this issue:
Affects: fedora-all [bug 1162575]
Affects: epel-all [bug 1162581]
---
Created arm-none-eabi-binutils-cs
Bugzilla
CVE-2014-8501 mingw-binutils: binutils: out-of-bounds write when parsing specially crafted PE executable [fedora-all]
bugzilla·2014-11-11·CVSS 7.5
CVE-2014-8501 [HIGH] CVE-2014-8501 mingw-binutils: binutils: out-of-bounds write when parsing specially crafted PE executable [fedora-all]
CVE-2014-8501 mingw-binutils: binutils: out-of-bounds write when parsing specially crafted PE executable [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue
http://lists.fedoraproject.org/pipermail/package-announce/2014-December/145262.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-December/145328.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-December/145742.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-January/147346.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-January/147354.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-January/148427.htmlhttp://secunia.com/advisories/62241http://secunia.com/advisories/62746http://www.mandriva.com/security/advisories?name=MDVSA-2015:029http://www.openwall.com/lists/oss-security/2014/10/26/3http://www.openwall.com/lists/oss-security/2014/10/31/1http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/70866http://www.ubuntu.com/usn/USN-2496-1https://bugzilla.redhat.com/show_bug.cgi?id=1162570https://security.gentoo.org/glsa/201612-24https://sourceware.org/bugzilla/show_bug.cgi?id=17512https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git%3Bh=7e1e19887abd24aeb15066b141cdff5541e0ec8ehttp://lists.fedoraproject.org/pipermail/package-announce/2014-December/145262.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-December/145328.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-December/145742.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-January/147346.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-January/147354.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-January/148427.htmlhttp://secunia.com/advisories/62241http://secunia.com/advisories/62746http://www.mandriva.com/security/advisories?name=MDVSA-2015:029http://www.openwall.com/lists/oss-security/2014/10/26/3http://www.openwall.com/lists/oss-security/2014/10/31/1http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/70866http://www.ubuntu.com/usn/USN-2496-1https://bugzilla.redhat.com/show_bug.cgi?id=1162570https://security.gentoo.org/glsa/201612-24https://sourceware.org/bugzilla/show_bug.cgi?id=17512https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git%3Bh=7e1e19887abd24aeb15066b141cdff5541e0ec8e
2014-12-09
Published