CVE-2014-8738
published 2015-01-15CVE-2014-8738: The _bfd_slurp_extended_name_table function in bfd/archive.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (invalid…
PriorityP426medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
5.21%
91.6th percentile
The _bfd_slurp_extended_name_table function in bfd/archive.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (invalid write, segmentation fault, and crash) via a crafted extended name table in an archive.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | binutils | < binutils 2.24.90.20141124-1 (bookworm) | binutils 2.24.90.20141124-1 (bookworm) |
| debian | binutils-mingw-w64 | < binutils 2.24.90.20141124-1 (bookworm) | binutils 2.24.90.20141124-1 (bookworm) |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| gnu | binutils | <= 2.24 | — |
| gnu | binutils | >= 0 < 2.24.90.20141124-1 | 2.24.90.20141124-1 |
| gnu | binutils | >= 0 < 2.24.90.20141124-1 | 2.24.90.20141124-1 |
| gnu | binutils | >= 0 < 2.24.90.20141124-1 | 2.24.90.20141124-1 |
| gnu | binutils | >= 0 < 2.24.90.20141124-1 | 2.24.90.20141124-1 |
| gnu | binutils | >= 0 < 2.24-5ubuntu3.1 | 2.24-5ubuntu3.1 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-p59q-qc7h-7hgg: The _bfd_slurp_extended_name_table function in bfd/archive
ghsa_unreviewed·2022-05-17
CVE-2014-8738 [MEDIUM] CWE-119 GHSA-p59q-qc7h-7hgg: The _bfd_slurp_extended_name_table function in bfd/archive
The _bfd_slurp_extended_name_table function in bfd/archive.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (invalid write, segmentation fault, and crash) via a crafted extended name table in an archive.
OSV
binutils vulnerabilities
osv·2015-02-09·CVSS 7.5
CVE-2014-8485 [HIGH] binutils vulnerabilities
binutils vulnerabilities
Michal Zalewski discovered that the setup_group function in libbfd in
GNU binutils did not properly check group headers in ELF files. An
attacker could use this to craft input that could cause a denial
of service (application crash) or possibly execute arbitrary code.
(CVE-2014-8485)
Hanno Böck discovered that the _bfd_XXi_swap_aouthdr_in function
in libbfd in GNU binutils allowed out-of-bounds writes. An
attacker could use this to craft input that could cause a denial
of service (application crash) or possibly execute arbitrary code.
(CVE-2014-8501)
Hanno Böck discovered a heap-based buffer overflow in the
pe_print_edata function in libbfd in GNU binutils. An attacker
could use this to craft input that could cause a denial of service
(application crash) or poss
OSV
CVE-2014-8738: The _bfd_slurp_extended_name_table function in bfd/archive
osv·2015-01-15·CVSS 5.0
CVE-2014-8738 [MEDIUM] CVE-2014-8738: The _bfd_slurp_extended_name_table function in bfd/archive
The _bfd_slurp_extended_name_table function in bfd/archive.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (invalid write, segmentation fault, and crash) via a crafted extended name table in an archive.
Ubuntu
GNU binutils vulnerabilities
vendor_ubuntu·2015-02-09·CVSS 7.5
CVE-2012-3509 [HIGH] GNU binutils vulnerabilities
Title: GNU binutils vulnerabilities
Summary: Applications from GNU binutils could be made to crash, run programs,
or delete arbitrary files as your login if they opened a specially
crafted file.
Michal Zalewski discovered that the setup_group function in libbfd in
GNU binutils did not properly check group headers in ELF files. An
attacker could use this to craft input that could cause a denial
of service (application crash) or possibly execute arbitrary code.
(CVE-2014-8485)
Hanno Böck discovered that the _bfd_XXi_swap_aouthdr_in function
in libbfd in GNU binutils allowed out-of-bounds writes. An
attacker could use this to craft input that could cause a denial
of service (application crash) or possibly execute arbitrary code.
(CVE-2014-8501)
Hanno Böck discovered a heap-based buffer ov
Red Hat
binutils: out of bounds memory write
vendor_redhat·2014-11-02·CVSS 5.0
CVE-2014-8738 [MEDIUM] CWE-787 binutils: out of bounds memory write
binutils: out of bounds memory write
The _bfd_slurp_extended_name_table function in bfd/archive.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (invalid write, segmentation fault, and crash) via a crafted extended name table in an archive.
A heap-based buffer overflow flaw was found in the way certain binutils utilities processed archive files. If a user were tricked into processing a specially crafted archive file, it could cause the utility used to process that archive to crash or, potentially, execute arbitrary code with the privileges of the user running that utility.
Statement: Red Hat Enterprise Linux 5 is now in Production 3 Phase of the support and maintenance life cycle. This has been rated as having Low security impact and is not current
Debian
CVE-2014-8738: binutils - The _bfd_slurp_extended_name_table function in bfd/archive.c in GNU binutils 2.2...
vendor_debian·2014·CVSS 5.0
CVE-2014-8738 [MEDIUM] CVE-2014-8738: binutils - The _bfd_slurp_extended_name_table function in bfd/archive.c in GNU binutils 2.2...
The _bfd_slurp_extended_name_table function in bfd/archive.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (invalid write, segmentation fault, and crash) via a crafted extended name table in an archive.
Scope: local
bookworm: resolved (fixed in 2.24.90.20141124-1)
bullseye: resolved (fixed in 2.24.90.20141124-1)
forky: resolved (fixed in 2.24.90.20141124-1)
sid: resolved (fixed in 2.24.90.20141124-1)
trixie: resolved (fixed in 2.24.90.20141124-1)
No detection rules found.
No public exploits indexed.
http://lists.fedoraproject.org/pipermail/package-announce/2015-January/147346.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-January/147354.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-January/148427.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-January/148438.htmlhttp://secunia.com/advisories/62241http://secunia.com/advisories/62746http://www.debian.org/security/2015/dsa-3123http://www.mandriva.com/security/advisories?name=MDVSA-2015:029http://www.openwall.com/lists/oss-security/2014/11/02/4http://www.openwall.com/lists/oss-security/2014/11/05/7http://www.openwall.com/lists/oss-security/2014/11/13/2http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/71083http://www.ubuntu.com/usn/USN-2496-1https://security.gentoo.org/glsa/201612-24https://sourceware.org/bugzilla/show_bug.cgi?id=17533https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git%3Bh=bb0d867169d7e9743d229804106a8fbcab7f3b3fhttp://lists.fedoraproject.org/pipermail/package-announce/2015-January/147346.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-January/147354.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-January/148427.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-January/148438.htmlhttp://secunia.com/advisories/62241http://secunia.com/advisories/62746http://www.debian.org/security/2015/dsa-3123http://www.mandriva.com/security/advisories?name=MDVSA-2015:029http://www.openwall.com/lists/oss-security/2014/11/02/4http://www.openwall.com/lists/oss-security/2014/11/05/7http://www.openwall.com/lists/oss-security/2014/11/13/2http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/71083http://www.ubuntu.com/usn/USN-2496-1https://security.gentoo.org/glsa/201612-24https://sourceware.org/bugzilla/show_bug.cgi?id=17533https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git%3Bh=bb0d867169d7e9743d229804106a8fbcab7f3b3f
2015-01-15
Published