CVE-2014-8737
published 2014-12-09CVE-2014-8737: Multiple directory traversal vulnerabilities in GNU binutils 2.24 and earlier allow local users to delete arbitrary files via a .. (dot dot) or full path name…
PriorityP417low3.6CVSS 2.0
AVLACLAuNCNIPAP
EPSS
1.04%
60.4th percentile
Multiple directory traversal vulnerabilities in GNU binutils 2.24 and earlier allow local users to delete arbitrary files via a .. (dot dot) or full path name in an archive to (1) strip or (2) objcopy or create arbitrary files via (3) a .. (dot dot) or full path name in an archive to ar.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | binutils | < binutils 2.24.90.20141124-1 (bookworm) | binutils 2.24.90.20141124-1 (bookworm) |
| debian | binutils-mingw-w64 | < binutils 2.24.90.20141124-1 (bookworm) | binutils 2.24.90.20141124-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| gnu | binutils | <= 2.24 | — |
| gnu | binutils | >= 0 < 2.24.90.20141124-1 | 2.24.90.20141124-1 |
| gnu | binutils | >= 0 < 2.24.90.20141124-1 | 2.24.90.20141124-1 |
| gnu | binutils | >= 0 < 2.24.90.20141124-1 | 2.24.90.20141124-1 |
| gnu | binutils | >= 0 < 2.24.90.20141124-1 | 2.24.90.20141124-1 |
| gnu | binutils | >= 0 < 2.24-5ubuntu3.1 | 2.24-5ubuntu3.1 |
CVSS provenance
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:N/I:P/A:P
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian3.6LOW
vendor_redhat3.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-p54r-q4hv-rx4g: Multiple directory traversal vulnerabilities in GNU binutils 2
ghsa_unreviewed·2022-05-17
CVE-2014-8737 [LOW] CWE-22 GHSA-p54r-q4hv-rx4g: Multiple directory traversal vulnerabilities in GNU binutils 2
Multiple directory traversal vulnerabilities in GNU binutils 2.24 and earlier allow local users to delete arbitrary files via a .. (dot dot) or full path name in an archive to (1) strip or (2) objcopy or create arbitrary files via (3) a .. (dot dot) or full path name in an archive to ar.
OSV
binutils vulnerabilities
osv·2015-02-09·CVSS 7.5
CVE-2014-8485 [HIGH] binutils vulnerabilities
binutils vulnerabilities
Michal Zalewski discovered that the setup_group function in libbfd in
GNU binutils did not properly check group headers in ELF files. An
attacker could use this to craft input that could cause a denial
of service (application crash) or possibly execute arbitrary code.
(CVE-2014-8485)
Hanno Böck discovered that the _bfd_XXi_swap_aouthdr_in function
in libbfd in GNU binutils allowed out-of-bounds writes. An
attacker could use this to craft input that could cause a denial
of service (application crash) or possibly execute arbitrary code.
(CVE-2014-8501)
Hanno Böck discovered a heap-based buffer overflow in the
pe_print_edata function in libbfd in GNU binutils. An attacker
could use this to craft input that could cause a denial of service
(application crash) or poss
OSV
CVE-2014-8737: Multiple directory traversal vulnerabilities in GNU binutils 2
osv·2014-12-09·CVSS 3.6
CVE-2014-8737 [LOW] CVE-2014-8737: Multiple directory traversal vulnerabilities in GNU binutils 2
Multiple directory traversal vulnerabilities in GNU binutils 2.24 and earlier allow local users to delete arbitrary files via a .. (dot dot) or full path name in an archive to (1) strip or (2) objcopy or create arbitrary files via (3) a .. (dot dot) or full path name in an archive to ar.
Ubuntu
GNU binutils vulnerabilities
vendor_ubuntu·2015-02-09·CVSS 7.5
CVE-2012-3509 [HIGH] GNU binutils vulnerabilities
Title: GNU binutils vulnerabilities
Summary: Applications from GNU binutils could be made to crash, run programs,
or delete arbitrary files as your login if they opened a specially
crafted file.
Michal Zalewski discovered that the setup_group function in libbfd in
GNU binutils did not properly check group headers in ELF files. An
attacker could use this to craft input that could cause a denial
of service (application crash) or possibly execute arbitrary code.
(CVE-2014-8485)
Hanno Böck discovered that the _bfd_XXi_swap_aouthdr_in function
in libbfd in GNU binutils allowed out-of-bounds writes. An
attacker could use this to craft input that could cause a denial
of service (application crash) or possibly execute arbitrary code.
(CVE-2014-8501)
Hanno Böck discovered a heap-based buffer ov
Red Hat
binutils: directory traversal vulnerability
vendor_redhat·2014-11-04·CVSS 3.6
CVE-2014-8737 [LOW] CWE-22 binutils: directory traversal vulnerability
binutils: directory traversal vulnerability
Multiple directory traversal vulnerabilities in GNU binutils 2.24 and earlier allow local users to delete arbitrary files via a .. (dot dot) or full path name in an archive to (1) strip or (2) objcopy or create arbitrary files via (3) a .. (dot dot) or full path name in an archive to ar.
A directory traversal flaw was found in the strip and objcopy utilities. A specially crafted file could cause strip or objdump to overwrite an arbitrary file writable by the user running either of these utilities.
Statement: Red Hat Enterprise Linux 5 is now in Production 3 Phase of the support and maintenance life cycle. This has been rated as having Moderate security impact and is not currently planned to be addressed in future updates. For additional inform
Debian
CVE-2014-8737: binutils - Multiple directory traversal vulnerabilities in GNU binutils 2.24 and earlier al...
vendor_debian·2014·CVSS 3.6
CVE-2014-8737 [LOW] CVE-2014-8737: binutils - Multiple directory traversal vulnerabilities in GNU binutils 2.24 and earlier al...
Multiple directory traversal vulnerabilities in GNU binutils 2.24 and earlier allow local users to delete arbitrary files via a .. (dot dot) or full path name in an archive to (1) strip or (2) objcopy or create arbitrary files via (3) a .. (dot dot) or full path name in an archive to ar.
Scope: local
bookworm: resolved (fixed in 2.24.90.20141124-1)
bullseye: resolved (fixed in 2.24.90.20141124-1)
forky: resolved (fixed in 2.24.90.20141124-1)
sid: resolved (fixed in 2.24.90.20141124-1)
trixie: resolved (fixed in 2.24.90.20141124-1)
No detection rules found.
No public exploits indexed.
http://lists.fedoraproject.org/pipermail/package-announce/2014-December/145256.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-December/145352.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-December/145746.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-January/147346.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-January/147354.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-January/148427.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-January/148438.htmlhttp://secunia.com/advisories/62241http://secunia.com/advisories/62746http://www.mandriva.com/security/advisories?name=MDVSA-2015:029http://www.openwall.com/lists/oss-security/2014/11/13/1http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/70908http://www.ubuntu.com/usn/USN-2496-1https://bugzilla.redhat.com/show_bug.cgi?id=1162655https://security.gentoo.org/glsa/201612-24https://sourceware.org/bugzilla/show_bug.cgi?id=17533https://sourceware.org/bugzilla/show_bug.cgi?id=17552https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git%3Bh=dd9b91de2149ee81d47f708e7b0bbf57da10ad42http://lists.fedoraproject.org/pipermail/package-announce/2014-December/145256.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-December/145352.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2014-December/145746.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-January/147346.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-January/147354.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-January/148427.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-January/148438.htmlhttp://secunia.com/advisories/62241http://secunia.com/advisories/62746http://www.mandriva.com/security/advisories?name=MDVSA-2015:029http://www.openwall.com/lists/oss-security/2014/11/13/1http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/70908http://www.ubuntu.com/usn/USN-2496-1https://bugzilla.redhat.com/show_bug.cgi?id=1162655https://security.gentoo.org/glsa/201612-24https://sourceware.org/bugzilla/show_bug.cgi?id=17533https://sourceware.org/bugzilla/show_bug.cgi?id=17552https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git%3Bh=dd9b91de2149ee81d47f708e7b0bbf57da10ad42
2014-12-09
Published