CVE-2014-9939Improper Restriction of Operations within the Bounds of a Memory Buffer in Binutils

Severity
9.8CRITICALNVD
EPSS
0.4%
top 40.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 21
Latest updateMay 17

Description

ihex.c in GNU Binutils before 2.26 contains a stack buffer overflow when printing bad bytes in Intel Hex objects.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages3 packages

Debiangnu/binutils< 2.25.90.20151125-1+3
NVDgnu/binutils2.25
Debiangnu/gdb< 7.10-1+3

Patches

🔴Vulnerability Details

4
GHSA
GHSA-84xq-q4jm-5r6c: ihex2022-05-17
OSV
gdb vulnerabilities2017-07-26
OSV
CVE-2014-9939: ihex2017-03-21
CVEList
CVE-2014-9939: ihex2017-03-21

📋Vendor Advisories

3
Ubuntu
gdb vulnerabilities2017-07-26
Red Hat
binutils: buffer overflow in ihex.c2015-07-31
Debian
CVE-2014-9939: binutils - ihex.c in GNU Binutils before 2.26 contains a stack buffer overflow when printin...2014

💬Community

1
Bugzilla
CVE-2014-9939 binutils: buffer overflow in ihex.c2015-08-04
CVE-2014-9939 — GNU Binutils vulnerability | cvebase