CVE-2014-8504
published 2014-12-09CVE-2014-8504: Stack-based buffer overflow in the srec_scan function in bfd/srec.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service…
PriorityP339high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
6.20%
92.7th percentile
Stack-based buffer overflow in the srec_scan function in bfd/srec.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly have other unspecified impact via a crafted file.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | binutils | < binutils 2.24.90.20141104-1 (bookworm) | binutils 2.24.90.20141104-1 (bookworm) |
| debian | binutils-mingw-w64 | < binutils 2.24.90.20141104-1 (bookworm) | binutils 2.24.90.20141104-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| gnu | binutils | <= 2.24 | — |
| gnu | binutils | >= 0 < 2.24.90.20141104-1 | 2.24.90.20141104-1 |
| gnu | binutils | >= 0 < 2.24.90.20141104-1 | 2.24.90.20141104-1 |
| gnu | binutils | >= 0 < 2.24.90.20141104-1 | 2.24.90.20141104-1 |
| gnu | binutils | >= 0 < 2.24.90.20141104-1 | 2.24.90.20141104-1 |
| gnu | binutils | >= 0 < 2.24-5ubuntu3.1 | 2.24-5ubuntu3.1 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mc28-wwxw-q97x: Stack-based buffer overflow in the srec_scan function in bfd/srec
ghsa_unreviewed·2022-05-17
CVE-2014-8504 [HIGH] CWE-119 GHSA-mc28-wwxw-q97x: Stack-based buffer overflow in the srec_scan function in bfd/srec
Stack-based buffer overflow in the srec_scan function in bfd/srec.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly have other unspecified impact via a crafted file.
OSV
binutils vulnerabilities
osv·2015-02-09·CVSS 7.5
CVE-2014-8485 [HIGH] binutils vulnerabilities
binutils vulnerabilities
Michal Zalewski discovered that the setup_group function in libbfd in
GNU binutils did not properly check group headers in ELF files. An
attacker could use this to craft input that could cause a denial
of service (application crash) or possibly execute arbitrary code.
(CVE-2014-8485)
Hanno Böck discovered that the _bfd_XXi_swap_aouthdr_in function
in libbfd in GNU binutils allowed out-of-bounds writes. An
attacker could use this to craft input that could cause a denial
of service (application crash) or possibly execute arbitrary code.
(CVE-2014-8501)
Hanno Böck discovered a heap-based buffer overflow in the
pe_print_edata function in libbfd in GNU binutils. An attacker
could use this to craft input that could cause a denial of service
(application crash) or poss
OSV
CVE-2014-8504: Stack-based buffer overflow in the srec_scan function in bfd/srec
osv·2014-12-09·CVSS 7.5
CVE-2014-8504 [HIGH] CVE-2014-8504: Stack-based buffer overflow in the srec_scan function in bfd/srec
Stack-based buffer overflow in the srec_scan function in bfd/srec.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly have other unspecified impact via a crafted file.
Ubuntu
GNU binutils vulnerabilities
vendor_ubuntu·2015-02-09·CVSS 7.5
CVE-2012-3509 [HIGH] GNU binutils vulnerabilities
Title: GNU binutils vulnerabilities
Summary: Applications from GNU binutils could be made to crash, run programs,
or delete arbitrary files as your login if they opened a specially
crafted file.
Michal Zalewski discovered that the setup_group function in libbfd in
GNU binutils did not properly check group headers in ELF files. An
attacker could use this to craft input that could cause a denial
of service (application crash) or possibly execute arbitrary code.
(CVE-2014-8485)
Hanno Böck discovered that the _bfd_XXi_swap_aouthdr_in function
in libbfd in GNU binutils allowed out-of-bounds writes. An
attacker could use this to craft input that could cause a denial
of service (application crash) or possibly execute arbitrary code.
(CVE-2014-8501)
Hanno Böck discovered a heap-based buffer ov
Red Hat
binutils: stack overflow in the SREC parser
vendor_redhat·2014-10-27·CVSS 7.5
CVE-2014-8504 [HIGH] CWE-121 binutils: stack overflow in the SREC parser
binutils: stack overflow in the SREC parser
Stack-based buffer overflow in the srec_scan function in bfd/srec.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly have other unspecified impact via a crafted file.
A stack-based buffer overflow flaw was found in the SREC parser of the libbfd library. A specially crafted file could cause an application using the libbfd library to crash or, potentially, execute arbitrary code with the privileges of the user running that application.
Statement: Red Hat Enterprise Linux 5 is now in Production 3 Phase of the support and maintenance life cycle. This has been rated as having Low security impact and is not currently planned to be addressed in future updates. For additional information, refer
Debian
CVE-2014-8504: binutils - Stack-based buffer overflow in the srec_scan function in bfd/srec.c in GNU binut...
vendor_debian·2014·CVSS 7.5
CVE-2014-8504 [HIGH] CVE-2014-8504: binutils - Stack-based buffer overflow in the srec_scan function in bfd/srec.c in GNU binut...
Stack-based buffer overflow in the srec_scan function in bfd/srec.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly have other unspecified impact via a crafted file.
Scope: local
bookworm: resolved (fixed in 2.24.90.20141104-1)
bullseye: resolved (fixed in 2.24.90.20141104-1)
forky: resolved (fixed in 2.24.90.20141104-1)
sid: resolved (fixed in 2.24.90.20141104-1)
trixie: resolved (fixed in 2.24.90.20141104-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-8504 arm-none-eabi-binutils-cs: binutils: stack overflow in the SREC parser [fedora-all]
bugzilla·2014-11-11·CVSS 7.5
CVE-2014-8504 [HIGH] CVE-2014-8504 arm-none-eabi-binutils-cs: binutils: stack overflow in the SREC parser [fedora-all]
CVE-2014-8504 arm-none-eabi-binutils-cs: binutils: stack overflow in the SREC parser [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple su
Bugzilla
CVE-2014-8504 binutils: stack overflow in the SREC parser [fedora-all]
bugzilla·2014-11-11·CVSS 7.5
CVE-2014-8504 [HIGH] CVE-2014-8504 binutils: stack overflow in the SREC parser [fedora-all]
CVE-2014-8504 binutils: stack overflow in the SREC parser [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora.
Bugzilla
CVE-2014-8504 msp430-binutils: binutils: stack overflow in the SREC parser [fedora-all]
bugzilla·2014-11-11·CVSS 7.5
CVE-2014-8504 [HIGH] CVE-2014-8504 msp430-binutils: binutils: stack overflow in the SREC parser [fedora-all]
CVE-2014-8504 msp430-binutils: binutils: stack overflow in the SREC parser [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported ve
Bugzilla
CVE-2014-8504 avr-binutils: binutils: stack overflow in the SREC parser [fedora-all]
bugzilla·2014-11-11·CVSS 7.5
CVE-2014-8504 [HIGH] CVE-2014-8504 avr-binutils: binutils: stack overflow in the SREC parser [fedora-all]
CVE-2014-8504 avr-binutils: binutils: stack overflow in the SREC parser [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versi
Bugzilla
CVE-2014-8504 binutils: stack overflow in the SREC parser
bugzilla·2014-11-11·CVSS 7.5
CVE-2014-8504 [HIGH] CVE-2014-8504 binutils: stack overflow in the SREC parser
CVE-2014-8504 binutils: stack overflow in the SREC parser
Stack overflow issue was reported [1] in SREC parser in binutils.
Upstream patch that fixes this issue is at [2].
Reproducer for this is available at http://lcamtuf.coredump.cx/strings-stack-overflow - just run "strings" utility on that crafted file.
[1]: https://sourceware.org/bugzilla/show_bug.cgi?id=17510#c7
[2]: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=708d7d0d11f0f2d776171979aa3479e8e12a38a0
Discussion:
Created mingw-binutils tracking bugs for this issue:
Affects: fedora-all [bug 1162626]
Affects: epel-all [bug 1162630]
---
Created avr-binutils tracking bugs for this issue:
Affects: fedora-all [bug 1162623]
Affects: epel-all [bug 1162628]
---
Created arm-none-eabi-binutils-cs tracking bugs for this i
Bugzilla
CVE-2014-8504 cross-binutils: binutils: stack overflow in the SREC parser [fedora-all]
bugzilla·2014-11-11·CVSS 7.5
CVE-2014-8504 [HIGH] CVE-2014-8504 cross-binutils: binutils: stack overflow in the SREC parser [fedora-all]
CVE-2014-8504 cross-binutils: binutils: stack overflow in the SREC parser [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported ver
Bugzilla
CVE-2014-8504 avr-binutils: binutils: stack overflow in the SREC parser [epel-all]
bugzilla·2014-11-11·CVSS 7.5
CVE-2014-8504 [HIGH] CVE-2014-8504 avr-binutils: binutils: stack overflow in the SREC parser [epel-all]
CVE-2014-8504 avr-binutils: binutils: stack overflow in the SREC parser [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported ve
Bugzilla
CVE-2014-8504 mingw-binutils: binutils: stack overflow in the SREC parser [epel-all]
bugzilla·2014-11-11·CVSS 7.5
CVE-2014-8504 [HIGH] CVE-2014-8504 mingw-binutils: binutils: stack overflow in the SREC parser [epel-all]
CVE-2014-8504 mingw-binutils: binutils: stack overflow in the SREC parser [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported
Bugzilla
CVE-2014-8504 cross-binutils: binutils: stack overflow in the SREC parser [epel-all]
bugzilla·2014-11-11·CVSS 7.5
CVE-2014-8504 [HIGH] CVE-2014-8504 cross-binutils: binutils: stack overflow in the SREC parser [epel-all]
CVE-2014-8504 cross-binutils: binutils: stack overflow in the SREC parser [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported
Bugzilla
CVE-2014-8504 mingw-binutils: binutils: stack overflow in the SREC parser [fedora-all]
bugzilla·2014-11-11·CVSS 7.5
CVE-2014-8504 [HIGH] CVE-2014-8504 mingw-binutils: binutils: stack overflow in the SREC parser [fedora-all]
CVE-2014-8504 mingw-binutils: binutils: stack overflow in the SREC parser [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported ver
http://lists.fedoraproject.org/pipermail/package-announce/2014-December/145262.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-December/145328.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-December/145742.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-January/147346.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-January/147354.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-January/148427.htmlhttp://secunia.com/advisories/62241http://secunia.com/advisories/62746http://www.mandriva.com/security/advisories?name=MDVSA-2015:029http://www.openwall.com/lists/oss-security/2014/10/27/4http://www.openwall.com/lists/oss-security/2014/10/27/5http://www.openwall.com/lists/oss-security/2014/10/31/1http://www.securityfocus.com/bid/70761http://www.ubuntu.com/usn/USN-2496-1https://bugzilla.redhat.com/show_bug.cgi?id=1162621https://security.gentoo.org/glsa/201612-24https://sourceware.org/bugzilla/show_bug.cgi?id=17510https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git%3Bh=708d7d0d11f0f2d776171979aa3479e8e12a38a0http://lists.fedoraproject.org/pipermail/package-announce/2014-December/145262.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-December/145328.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-December/145742.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-January/147346.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-January/147354.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-January/148427.htmlhttp://secunia.com/advisories/62241http://secunia.com/advisories/62746http://www.mandriva.com/security/advisories?name=MDVSA-2015:029http://www.openwall.com/lists/oss-security/2014/10/27/4http://www.openwall.com/lists/oss-security/2014/10/27/5http://www.openwall.com/lists/oss-security/2014/10/31/1http://www.securityfocus.com/bid/70761http://www.ubuntu.com/usn/USN-2496-1https://bugzilla.redhat.com/show_bug.cgi?id=1162621https://security.gentoo.org/glsa/201612-24https://sourceware.org/bugzilla/show_bug.cgi?id=17510https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git%3Bh=708d7d0d11f0f2d776171979aa3479e8e12a38a0
2014-12-09
Published