CVE-2014-9939
published 2017-03-21CVE-2014-9939: ihex.c in GNU Binutils before 2.26 contains a stack buffer overflow when printing bad bytes in Intel Hex objects.
PriorityP346critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
2.28%
81.2th percentile
ihex.c in GNU Binutils before 2.26 contains a stack buffer overflow when printing bad bytes in Intel Hex objects.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | binutils | < binutils 2.25.90.20151125-1 (bookworm) | binutils 2.25.90.20151125-1 (bookworm) |
| debian | gdb | < binutils 2.25.90.20151125-1 (bookworm) | binutils 2.25.90.20151125-1 (bookworm) |
| gnu | binutils | <= 2.25 | — |
| gnu | binutils | >= 0 < 2.25.90.20151125-1 | 2.25.90.20151125-1 |
| gnu | binutils | >= 0 < 2.25.90.20151125-1 | 2.25.90.20151125-1 |
| gnu | binutils | >= 0 < 2.25.90.20151125-1 | 2.25.90.20151125-1 |
| gnu | binutils | >= 0 < 2.25.90.20151125-1 | 2.25.90.20151125-1 |
| gnu | gdb | >= 0 < 7.10-1 | 7.10-1 |
| gnu | gdb | >= 0 < 7.10-1 | 7.10-1 |
| gnu | gdb | >= 0 < 7.10-1 | 7.10-1 |
| gnu | gdb | >= 0 < 7.10-1 | 7.10-1 |
| gnu | gdb | >= 0 < 7.7.1-0ubuntu5~14.04.3 | 7.7.1-0ubuntu5~14.04.3 |
| gnu | gdb | >= 0 < 7.11.1-0ubuntu1~16.5 | 7.11.1-0ubuntu1~16.5 |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
gdb vulnerabilities
vendor_ubuntu·2017-07-26·CVSS 7.5
CVE-2014-8501 [HIGH] gdb vulnerabilities
Title: gdb vulnerabilities
Summary: Several security issues were fixed in gdb.
Hanno Böck discovered that gdb incorrectly handled certain malformed AOUT
headers in PE executables. If a user or automated system were tricked into
processing a specially crafted binary, a remote attacker could use this
issue to cause gdb to crash, resulting in a denial of service, or possibly
execute arbitrary code. This issue only applied to Ubuntu 14.04 LTS.
(CVE-2014-8501)
It was discovered that gdb incorrectly handled printing bad bytes in Intel
Hex objects. If a user or automated system were tricked into processing a
specially crafted binary, a remote attacker could use this issue to cause
gdb to crash, resulting in a denial of service. This issue only applied to
Ubuntu 14.04 LTS. (CVE-2014-9939)
It w
Red Hat
binutils: buffer overflow in ihex.c
vendor_redhat·2015-07-31·CVSS 9.8
CVE-2014-9939 [CRITICAL] CWE-121 binutils: buffer overflow in ihex.c
binutils: buffer overflow in ihex.c
ihex.c in GNU Binutils before 2.26 contains a stack buffer overflow when printing bad bytes in Intel Hex objects.
Statement: This issue affects the versions of binutils as shipped with Red Hat Enterprise Linux 5, 6, and 7. Red Hat Product Security has rated this issue as having Low security impact. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: binutils (Red Hat Enterprise Linux 5) - Will not fix
Package: binutils220 (Red Hat Enterprise Linux 5) - Will not fix
Package: binutils (Red Hat Enterprise Linux 6) - Will not fix
Package: binutils (Red Hat Enterprise Linux 7) - Affected
Debian
CVE-2014-9939: binutils - ihex.c in GNU Binutils before 2.26 contains a stack buffer overflow when printin...
vendor_debian·2014·CVSS 9.8
CVE-2014-9939 [CRITICAL] CVE-2014-9939: binutils - ihex.c in GNU Binutils before 2.26 contains a stack buffer overflow when printin...
ihex.c in GNU Binutils before 2.26 contains a stack buffer overflow when printing bad bytes in Intel Hex objects.
Scope: local
bookworm: resolved (fixed in 2.25.90.20151125-1)
bullseye: resolved (fixed in 2.25.90.20151125-1)
forky: resolved (fixed in 2.25.90.20151125-1)
sid: resolved (fixed in 2.25.90.20151125-1)
trixie: resolved (fixed in 2.25.90.20151125-1)
GHSA
GHSA-84xq-q4jm-5r6c: ihex
ghsa_unreviewed·2022-05-17
CVE-2014-9939 [CRITICAL] CWE-119 GHSA-84xq-q4jm-5r6c: ihex
ihex.c in GNU Binutils before 2.26 contains a stack buffer overflow when printing bad bytes in Intel Hex objects.
OSV
gdb vulnerabilities
osv·2017-07-26·CVSS 7.5
CVE-2014-8501 [HIGH] gdb vulnerabilities
gdb vulnerabilities
Hanno Böck discovered that gdb incorrectly handled certain malformed AOUT
headers in PE executables. If a user or automated system were tricked into
processing a specially crafted binary, a remote attacker could use this
issue to cause gdb to crash, resulting in a denial of service, or possibly
execute arbitrary code. This issue only applied to Ubuntu 14.04 LTS.
(CVE-2014-8501)
It was discovered that gdb incorrectly handled printing bad bytes in Intel
Hex objects. If a user or automated system were tricked into processing a
specially crafted binary, a remote attacker could use this issue to cause
gdb to crash, resulting in a denial of service. This issue only applied to
Ubuntu 14.04 LTS. (CVE-2014-9939)
It was discovered that gdb incorrectly handled certain string op
OSV
CVE-2014-9939: ihex
osv·2017-03-21·CVSS 9.8
CVE-2014-9939 [CRITICAL] CVE-2014-9939: ihex
ihex.c in GNU Binutils before 2.26 contains a stack buffer overflow when printing bad bytes in Intel Hex objects.
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2015/07/31/6https://sourceware.org/bugzilla/show_bug.cgi?id=18750https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git%3Bh=7e27a9d5f22f9f7ead11738b1546d0b5c737266bhttp://www.openwall.com/lists/oss-security/2015/07/31/6https://sourceware.org/bugzilla/show_bug.cgi?id=18750https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git%3Bh=7e27a9d5f22f9f7ead11738b1546d0b5c737266b
2017-03-21
Published