CVE-2014-8503
published 2014-12-09CVE-2014-8503: Stack-based buffer overflow in the ihex_scan function in bfd/ihex.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service…
PriorityP339high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
6.20%
92.7th percentile
Stack-based buffer overflow in the ihex_scan function in bfd/ihex.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly have other unspecified impact via a crafted ihex file.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | binutils | < binutils 2.24.90.20141104-1 (bookworm) | binutils 2.24.90.20141104-1 (bookworm) |
| debian | binutils-mingw-w64 | < binutils 2.24.90.20141104-1 (bookworm) | binutils 2.24.90.20141104-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| gnu | binutils | <= 2.24 | — |
| gnu | binutils | >= 0 < 2.24.90.20141104-1 | 2.24.90.20141104-1 |
| gnu | binutils | >= 0 < 2.24.90.20141104-1 | 2.24.90.20141104-1 |
| gnu | binutils | >= 0 < 2.24.90.20141104-1 | 2.24.90.20141104-1 |
| gnu | binutils | >= 0 < 2.24.90.20141104-1 | 2.24.90.20141104-1 |
| gnu | binutils | >= 0 < 2.24-5ubuntu3.1 | 2.24-5ubuntu3.1 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wm8r-9c6v-49f4: Stack-based buffer overflow in the ihex_scan function in bfd/ihex
ghsa_unreviewed·2022-05-17
CVE-2014-8503 [HIGH] CWE-119 GHSA-wm8r-9c6v-49f4: Stack-based buffer overflow in the ihex_scan function in bfd/ihex
Stack-based buffer overflow in the ihex_scan function in bfd/ihex.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly have other unspecified impact via a crafted ihex file.
OSV
binutils vulnerabilities
osv·2015-02-09·CVSS 7.5
CVE-2014-8485 [HIGH] binutils vulnerabilities
binutils vulnerabilities
Michal Zalewski discovered that the setup_group function in libbfd in
GNU binutils did not properly check group headers in ELF files. An
attacker could use this to craft input that could cause a denial
of service (application crash) or possibly execute arbitrary code.
(CVE-2014-8485)
Hanno Böck discovered that the _bfd_XXi_swap_aouthdr_in function
in libbfd in GNU binutils allowed out-of-bounds writes. An
attacker could use this to craft input that could cause a denial
of service (application crash) or possibly execute arbitrary code.
(CVE-2014-8501)
Hanno Böck discovered a heap-based buffer overflow in the
pe_print_edata function in libbfd in GNU binutils. An attacker
could use this to craft input that could cause a denial of service
(application crash) or poss
OSV
CVE-2014-8503: Stack-based buffer overflow in the ihex_scan function in bfd/ihex
osv·2014-12-09·CVSS 7.5
CVE-2014-8503 [HIGH] CVE-2014-8503: Stack-based buffer overflow in the ihex_scan function in bfd/ihex
Stack-based buffer overflow in the ihex_scan function in bfd/ihex.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly have other unspecified impact via a crafted ihex file.
Ubuntu
GNU binutils vulnerabilities
vendor_ubuntu·2015-02-09·CVSS 7.5
CVE-2012-3509 [HIGH] GNU binutils vulnerabilities
Title: GNU binutils vulnerabilities
Summary: Applications from GNU binutils could be made to crash, run programs,
or delete arbitrary files as your login if they opened a specially
crafted file.
Michal Zalewski discovered that the setup_group function in libbfd in
GNU binutils did not properly check group headers in ELF files. An
attacker could use this to craft input that could cause a denial
of service (application crash) or possibly execute arbitrary code.
(CVE-2014-8485)
Hanno Böck discovered that the _bfd_XXi_swap_aouthdr_in function
in libbfd in GNU binutils allowed out-of-bounds writes. An
attacker could use this to craft input that could cause a denial
of service (application crash) or possibly execute arbitrary code.
(CVE-2014-8501)
Hanno Böck discovered a heap-based buffer ov
Red Hat
binutils: stack overflow in objdump when parsing specially crafted ihex file
vendor_redhat·2014-10-30·CVSS 7.5
CVE-2014-8503 [HIGH] CWE-121 binutils: stack overflow in objdump when parsing specially crafted ihex file
binutils: stack overflow in objdump when parsing specially crafted ihex file
Stack-based buffer overflow in the ihex_scan function in bfd/ihex.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly have other unspecified impact via a crafted ihex file.
A stack-based buffer overflow flaw was found in the way objdump processed IHEX files. A specially crafted IHEX file could cause objdump to crash or, potentially, execute arbitrary code with the privileges of the user running objdump.
Statement: Red Hat Enterprise Linux 5 is now in Production 3 Phase of the support and maintenance life cycle. This has been rated as having Low security impact and is not currently planned to be addressed in future updates. For additional information, refe
Debian
CVE-2014-8503: binutils - Stack-based buffer overflow in the ihex_scan function in bfd/ihex.c in GNU binut...
vendor_debian·2014·CVSS 7.5
CVE-2014-8503 [HIGH] CVE-2014-8503: binutils - Stack-based buffer overflow in the ihex_scan function in bfd/ihex.c in GNU binut...
Stack-based buffer overflow in the ihex_scan function in bfd/ihex.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly have other unspecified impact via a crafted ihex file.
Scope: local
bookworm: resolved (fixed in 2.24.90.20141104-1)
bullseye: resolved (fixed in 2.24.90.20141104-1)
forky: resolved (fixed in 2.24.90.20141104-1)
sid: resolved (fixed in 2.24.90.20141104-1)
trixie: resolved (fixed in 2.24.90.20141104-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-8503 msp430-binutils: binutils: stack overflow in objdump when parsing specially crafted ihex file [fedora-all]
bugzilla·2014-11-11·CVSS 7.5
CVE-2014-8503 [HIGH] CVE-2014-8503 msp430-binutils: binutils: stack overflow in objdump when parsing specially crafted ihex file [fedora-all]
CVE-2014-8503 msp430-binutils: binutils: stack overflow in objdump when parsing specially crafted ihex file [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this is
Bugzilla
CVE-2014-8503 mingw-binutils: binutils: stack overflow in objdump when parsing specially crafted ihex file [fedora-all]
bugzilla·2014-11-11·CVSS 7.5
CVE-2014-8503 [HIGH] CVE-2014-8503 mingw-binutils: binutils: stack overflow in objdump when parsing specially crafted ihex file [fedora-all]
CVE-2014-8503 mingw-binutils: binutils: stack overflow in objdump when parsing specially crafted ihex file [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this iss
Bugzilla
CVE-2014-8503 avr-binutils: binutils: stack overflow in objdump when parsing specially crafted ihex file [fedora-all]
bugzilla·2014-11-11·CVSS 7.5
CVE-2014-8503 [HIGH] CVE-2014-8503 avr-binutils: binutils: stack overflow in objdump when parsing specially crafted ihex file [fedora-all]
CVE-2014-8503 avr-binutils: binutils: stack overflow in objdump when parsing specially crafted ihex file [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue
Bugzilla
CVE-2014-8503 binutils: stack overflow in objdump when parsing specially crafted ihex file [fedora-all]
bugzilla·2014-11-11·CVSS 7.5
CVE-2014-8503 [HIGH] CVE-2014-8503 binutils: stack overflow in objdump when parsing specially crafted ihex file [fedora-all]
CVE-2014-8503 binutils: stack overflow in objdump when parsing specially crafted ihex file [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multi
Bugzilla
CVE-2014-8503 cross-binutils: binutils: stack overflow in objdump when parsing specially crafted ihex file [epel-all]
bugzilla·2014-11-11·CVSS 7.5
CVE-2014-8503 [HIGH] CVE-2014-8503 cross-binutils: binutils: stack overflow in objdump when parsing specially crafted ihex file [epel-all]
CVE-2014-8503 cross-binutils: binutils: stack overflow in objdump when parsing specially crafted ihex file [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this
Bugzilla
CVE-2014-8503 binutils: stack overflow in objdump when parsing specially crafted ihex file
bugzilla·2014-11-11·CVSS 7.5
CVE-2014-8503 [HIGH] CVE-2014-8503 binutils: stack overflow in objdump when parsing specially crafted ihex file
CVE-2014-8503 binutils: stack overflow in objdump when parsing specially crafted ihex file
Stack overflow was reported [1] in objdump when parsing a crafted ihex file [2].
Upstream patch is at [3].
[1]: https://sourceware.org/bugzilla/show_bug.cgi?id=17512#c33
[2]: https://sourceware.org/bugzilla/attachment.cgi?id=7869
[3]: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=0102ea8cec5fc509bba6c91df61b7ce23a799d32
Discussion:
Created avr-binutils tracking bugs for this issue:
Affects: epel-all [bug 1162617]
---
Created cross-binutils tracking bugs for this issue:
Affects: epel-all [bug 1162618]
---
Created mingw-binutils tracking bugs for this issue:
Affects: epel-all [bug 1162619]
---
Statement:
Red Hat Enterprise Linux 5 is now in Production 3 Phase of the support a
Bugzilla
CVE-2014-8503 avr-binutils: binutils: stack overflow in objdump when parsing specially crafted ihex file [epel-all]
bugzilla·2014-11-11·CVSS 7.5
CVE-2014-8503 [HIGH] CVE-2014-8503 avr-binutils: binutils: stack overflow in objdump when parsing specially crafted ihex file [epel-all]
CVE-2014-8503 avr-binutils: binutils: stack overflow in objdump when parsing specially crafted ihex file [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this is
Bugzilla
CVE-2014-8503 cross-binutils: binutils: stack overflow in objdump when parsing specially crafted ihex file [fedora-all]
bugzilla·2014-11-11·CVSS 7.5
CVE-2014-8503 [HIGH] CVE-2014-8503 cross-binutils: binutils: stack overflow in objdump when parsing specially crafted ihex file [fedora-all]
CVE-2014-8503 cross-binutils: binutils: stack overflow in objdump when parsing specially crafted ihex file [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this iss
Bugzilla
CVE-2014-8503 arm-none-eabi-binutils-cs: binutils: stack overflow in objdump when parsing specially crafted ihex file [fedora-all]
bugzilla·2014-11-11·CVSS 7.5
CVE-2014-8503 [HIGH] CVE-2014-8503 arm-none-eabi-binutils-cs: binutils: stack overflow in objdump when parsing specially crafted ihex file [fedora-all]
CVE-2014-8503 arm-none-eabi-binutils-cs: binutils: stack overflow in objdump when parsing specially crafted ihex file [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOT
Bugzilla
CVE-2014-8503 mingw-binutils: binutils: stack overflow in objdump when parsing specially crafted ihex file [epel-all]
bugzilla·2014-11-11·CVSS 7.5
CVE-2014-8503 [HIGH] CVE-2014-8503 mingw-binutils: binutils: stack overflow in objdump when parsing specially crafted ihex file [epel-all]
CVE-2014-8503 mingw-binutils: binutils: stack overflow in objdump when parsing specially crafted ihex file [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this
http://lists.fedoraproject.org/pipermail/package-announce/2014-December/145262.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-December/145328.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-December/145742.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-January/147346.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-January/147354.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-January/148427.htmlhttp://secunia.com/advisories/62241http://secunia.com/advisories/62746http://www.mandriva.com/security/advisories?name=MDVSA-2015:029http://www.openwall.com/lists/oss-security/2014/10/31/1http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/70868http://www.ubuntu.com/usn/USN-2496-1https://bugzilla.redhat.com/show_bug.cgi?id=1162607https://security.gentoo.org/glsa/201612-24https://sourceware.org/bugzilla/show_bug.cgi?id=17512https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git%3Ba=commit%3Bh=0102ea8cec5fc509bba6c91df61b7ce23a799d32http://lists.fedoraproject.org/pipermail/package-announce/2014-December/145262.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-December/145328.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-December/145742.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-January/147346.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-January/147354.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-January/148427.htmlhttp://secunia.com/advisories/62241http://secunia.com/advisories/62746http://www.mandriva.com/security/advisories?name=MDVSA-2015:029http://www.openwall.com/lists/oss-security/2014/10/31/1http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/70868http://www.ubuntu.com/usn/USN-2496-1https://bugzilla.redhat.com/show_bug.cgi?id=1162607https://security.gentoo.org/glsa/201612-24https://sourceware.org/bugzilla/show_bug.cgi?id=17512https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git%3Ba=commit%3Bh=0102ea8cec5fc509bba6c91df61b7ce23a799d32
2014-12-09
Published