CVE-2016-2226
published 2017-02-24CVE-2016-2226: Integer overflow in the string_appends function in cplus-dem.c in libiberty allows remote attackers to execute arbitrary code via a crafted executable, which…
PriorityP347high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EXPLOIT
EPSS
7.27%
93.7th percentile
Integer overflow in the string_appends function in cplus-dem.c in libiberty allows remote attackers to execute arbitrary code via a crafted executable, which triggers a buffer overflow.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | binutils | < binutils 2.27.51.20161102-1 (bookworm) | binutils 2.27.51.20161102-1 (bookworm) |
| debian | ht | < binutils 2.27.51.20161102-1 (bookworm) | binutils 2.27.51.20161102-1 (bookworm) |
| debian | libiberty | < binutils 2.27.51.20161102-1 (bookworm) | binutils 2.27.51.20161102-1 (bookworm) |
| gnu | binutils | >= 0 < 2.27.51.20161102-1 | 2.27.51.20161102-1 |
| gnu | binutils | >= 0 < 2.27.51.20161102-1 | 2.27.51.20161102-1 |
| gnu | binutils | >= 0 < 2.27.51.20161102-1 | 2.27.51.20161102-1 |
| gnu | binutils | >= 0 < 2.27.51.20161102-1 | 2.27.51.20161102-1 |
| gnu | gdb | >= 0 < 7.7.1-0ubuntu5~14.04.3 | 7.7.1-0ubuntu5~14.04.3 |
| gnu | gdb | >= 0 < 7.11.1-0ubuntu1~16.5 | 7.11.1-0ubuntu1~16.5 |
| valgrind | valgrind | >= 0 < 1:3.10.1-1ubuntu3~14.5 | 1:3.10.1-1ubuntu3~14.5 |
| valgrind | valgrind | >= 0 < 1:3.11.0-1ubuntu4.2 | 1:3.11.0-1ubuntu4.2 |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8LOW
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pcjp-97ph-pm6p: Integer overflow in the string_appends function in cplus-dem
ghsa_unreviewed·2022-05-17
CVE-2016-2226 [HIGH] CWE-119 GHSA-pcjp-97ph-pm6p: Integer overflow in the string_appends function in cplus-dem
Integer overflow in the string_appends function in cplus-dem.c in libiberty allows remote attackers to execute arbitrary code via a crafted executable, which triggers a buffer overflow.
OSV
gdb vulnerabilities
osv·2017-07-26·CVSS 7.5
CVE-2014-8501 [HIGH] gdb vulnerabilities
gdb vulnerabilities
Hanno Böck discovered that gdb incorrectly handled certain malformed AOUT
headers in PE executables. If a user or automated system were tricked into
processing a specially crafted binary, a remote attacker could use this
issue to cause gdb to crash, resulting in a denial of service, or possibly
execute arbitrary code. This issue only applied to Ubuntu 14.04 LTS.
(CVE-2014-8501)
It was discovered that gdb incorrectly handled printing bad bytes in Intel
Hex objects. If a user or automated system were tricked into processing a
specially crafted binary, a remote attacker could use this issue to cause
gdb to crash, resulting in a denial of service. This issue only applied to
Ubuntu 14.04 LTS. (CVE-2014-9939)
It was discovered that gdb incorrectly handled certain string op
OSV
libiberty vulnerabilities
osv·2017-07-26·CVSS 7.8
CVE-2016-2226 [HIGH] libiberty vulnerabilities
libiberty vulnerabilities
It was discovered that libiberty incorrectly handled certain string
operations. If a user or automated system were tricked into processing a
specially crafted binary, a remote attacker could use this issue to cause
libiberty to crash, resulting in a denial of service, or possibly execute
arbitrary code. This issue only applied to Ubuntu 14.04 LTS and Ubuntu
16.04 LTS. (CVE-2016-2226)
It was discovered that libiberty incorrectly handled parsing certain
binaries. If a user or automated system were tricked into processing a
specially crafted binary, a remote attacker could use this issue to cause
libiberty to crash, resulting in a denial of service. This issue only
applied to Ubuntu 14.04 LTS and Ubuntu 16.04 LTS. (CVE-2016-4487,
CVE-2016-4488, CVE-2016-4489, CVE-2
OSV
valgrind vulnerabilities
osv·2017-06-21·CVSS 7.8
CVE-2016-2226 [HIGH] valgrind vulnerabilities
valgrind vulnerabilities
It was discovered that Valgrind incorrectly handled certain string
operations. If a user or automated system were tricked into processing a
specially crafted binary, a remote attacker could possibly execute
arbitrary code. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04
LTS and Ubuntu 16.10. (CVE-2016-2226)
It was discovered that Valgrind incorrectly handled parsing certain
binaries. If a user or automated system were tricked into processing a
specially crafted binary, a remote attacker could use this issue to cause
Valgrind to crash, resulting in a denial of service. (CVE-2016-4487,
CVE-2016-4488, CVE-2016-4489, CVE-2016-4490, CVE-2016-4491, CVE-2016-4492,
CVE-2016-4493, CVE-2016-6131)
OSV
CVE-2016-2226: Integer overflow in the string_appends function in cplus-dem
osv·2017-02-24·CVSS 7.8
CVE-2016-2226 [HIGH] CVE-2016-2226: Integer overflow in the string_appends function in cplus-dem
Integer overflow in the string_appends function in cplus-dem.c in libiberty allows remote attackers to execute arbitrary code via a crafted executable, which triggers a buffer overflow.
Ubuntu
GNU binutils vulnerabilities
vendor_ubuntu·2021-07-21
CVE-2018-19932 GNU binutils vulnerabilities
Title: GNU binutils vulnerabilities
Summary: Several security issues were fixed in GNU binutils.
USN-4336-1 fixed several vulnerabilities in GNU binutils. This update provides
the corresponding update for Ubuntu 16.04 ESM.
Original advisory details:
It was discovered that GNU binutils contained a large number of security
issues. If a user or automated system were tricked into processing a
specially-crafted file, a remote attacker could cause GNU binutils to
crash, resulting in a denial of service, or possibly execute arbitrary
code.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
gdb vulnerabilities
vendor_ubuntu·2017-07-26·CVSS 7.5
CVE-2014-8501 [HIGH] gdb vulnerabilities
Title: gdb vulnerabilities
Summary: Several security issues were fixed in gdb.
Hanno Böck discovered that gdb incorrectly handled certain malformed AOUT
headers in PE executables. If a user or automated system were tricked into
processing a specially crafted binary, a remote attacker could use this
issue to cause gdb to crash, resulting in a denial of service, or possibly
execute arbitrary code. This issue only applied to Ubuntu 14.04 LTS.
(CVE-2014-8501)
It was discovered that gdb incorrectly handled printing bad bytes in Intel
Hex objects. If a user or automated system were tricked into processing a
specially crafted binary, a remote attacker could use this issue to cause
gdb to crash, resulting in a denial of service. This issue only applied to
Ubuntu 14.04 LTS. (CVE-2014-9939)
It w
Ubuntu
libiberty vulnerabilities
vendor_ubuntu·2017-07-26·CVSS 7.8
CVE-2016-2226 [HIGH] libiberty vulnerabilities
Title: libiberty vulnerabilities
Summary: Several security issues were fixed in libiberty.
It was discovered that libiberty incorrectly handled certain string
operations. If a user or automated system were tricked into processing a
specially crafted binary, a remote attacker could use this issue to cause
libiberty to crash, resulting in a denial of service, or possibly execute
arbitrary code. This issue only applied to Ubuntu 14.04 LTS and Ubuntu
16.04 LTS. (CVE-2016-2226)
It was discovered that libiberty incorrectly handled parsing certain
binaries. If a user or automated system were tricked into processing a
specially crafted binary, a remote attacker could use this issue to cause
libiberty to crash, resulting in a denial of service. This issue only
applied to Ubuntu 14.04 LTS and Ubu
Ubuntu
Valgrind vulnerabilities
vendor_ubuntu·2017-06-21·CVSS 7.8
CVE-2016-2226 [HIGH] Valgrind vulnerabilities
Title: Valgrind vulnerabilities
Summary: Valgrind could be made to crash or run programs if it opened a specially
crafted file.
It was discovered that Valgrind incorrectly handled certain string
operations. If a user or automated system were tricked into processing a
specially crafted binary, a remote attacker could possibly execute
arbitrary code. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04
LTS and Ubuntu 16.10. (CVE-2016-2226)
It was discovered that Valgrind incorrectly handled parsing certain
binaries. If a user or automated system were tricked into processing a
specially crafted binary, a remote attacker could use this issue to cause
Valgrind to crash, resulting in a denial of service. (CVE-2016-4487,
CVE-2016-4488, CVE-2016-4489, CVE-2016-4490, CVE-2016-4491, CVE-2016-4
Red Hat
openjpeg2: Multiple security issues
vendor_redhat·2016-10-27·CVSS 6.5
CVE-2016-9116 [MEDIUM] openjpeg2: Multiple security issues
openjpeg2: Multiple security issues
NULL Pointer Access in function imagetopnm of convert.c:2226(jp2) in OpenJPEG 2.1.2. Impact is Denial of Service. Someone must open a crafted j2k file.
Package: openjpeg (Red Hat Enterprise Linux 6) - Not affected
Package: openjpeg (Red Hat Enterprise Linux 7) - Not affected
Red Hat
gcc: Exploitable buffer overflow
vendor_redhat·2016-02-05·CVSS 7.8
CVE-2016-2226 [HIGH] CWE-122 gcc: Exploitable buffer overflow
gcc: Exploitable buffer overflow
Integer overflow in the string_appends function in cplus-dem.c in libiberty allows remote attackers to execute arbitrary code via a crafted executable, which triggers a buffer overflow.
Statement: Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: binutils (Red Hat Enterprise Linux 5) - Will not fix
Package: compat-gcc-295 (Red Hat Enterprise Linux 5) - Will not fix
Package: compat-gcc-296 (Red Hat Enterprise Linux 5) - Will not fix
Package: compat-gcc-32 (Red Hat Enterprise Linux 5) - Will not fix
Package: compat-gc
Debian
CVE-2016-2226: binutils - Integer overflow in the string_appends function in cplus-dem.c in libiberty allo...
vendor_debian·2016·CVSS 7.8
CVE-2016-2226 [HIGH] CVE-2016-2226: binutils - Integer overflow in the string_appends function in cplus-dem.c in libiberty allo...
Integer overflow in the string_appends function in cplus-dem.c in libiberty allows remote attackers to execute arbitrary code via a crafted executable, which triggers a buffer overflow.
Scope: local
bookworm: resolved (fixed in 2.27.51.20161102-1)
bullseye: resolved (fixed in 2.27.51.20161102-1)
forky: resolved (fixed in 2.27.51.20161102-1)
sid: resolved (fixed in 2.27.51.20161102-1)
trixie: resolved (fixed in 2.27.51.20161102-1)
No detection rules found.
Bugzilla
CVE-2016-2226 CVE-2016-4487 CVE-2016-4488 CVE-2016-4489 CVE-2016-4490 CVE-2016-4491 CVE-2016-4492 CVE-2016-4493 mingw-gcc: various flaws [epel-all]
bugzilla·2016-05-05·CVSS 7.8
CVE-2016-2226 [HIGH] CVE-2016-2226 CVE-2016-4487 CVE-2016-4488 CVE-2016-4489 CVE-2016-4490 CVE-2016-4491 CVE-2016-4492 CVE-2016-4493 mingw-gcc: various flaws [epel-all]
CVE-2016-2226 CVE-2016-4487 CVE-2016-4488 CVE-2016-4489 CVE-2016-4490 CVE-2016-4491 CVE-2016-4492 CVE-2016-4493 mingw-gcc: various flaws [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpk
Bugzilla
CVE-2016-2226 CVE-2016-4487 CVE-2016-4488 CVE-2016-4489 CVE-2016-4490 CVE-2016-4491 CVE-2016-4492 CVE-2016-4493 msp430-gcc: various flaws [fedora-all]
bugzilla·2016-05-05·CVSS 7.8
CVE-2016-2226 [HIGH] CVE-2016-2226 CVE-2016-4487 CVE-2016-4488 CVE-2016-4489 CVE-2016-4490 CVE-2016-4491 CVE-2016-4492 CVE-2016-4493 msp430-gcc: various flaws [fedora-all]
CVE-2016-2226 CVE-2016-4487 CVE-2016-4488 CVE-2016-4489 CVE-2016-4490 CVE-2016-4491 CVE-2016-4492 CVE-2016-4493 msp430-gcc: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg
Bugzilla
CVE-2016-2226 gcc: Exploitable buffer overflow
bugzilla·2016-05-05·CVSS 7.8
CVE-2016-2226 [HIGH] CVE-2016-2226 gcc: Exploitable buffer overflow
CVE-2016-2226 gcc: Exploitable buffer overflow
A vulnerability was found in libiberty when demangling some specific mangled functions. A particularly malicious attacker could craft an executable that executes when *analysed* by objdump, nm or gdb, or any other libiberty-based forensics tool (if the demangling option is switched on).
External references:
https://gcc.gnu.org/bugzilla/show_bug.cgi?id=69687
References:
http://seclists.org/oss-sec/2016/q2/238
Upstream fix:
https://gcc.gnu.org/viewcvs/gcc?view=revision&revision=234829
Discussion:
Created msp430-gcc tracking bugs for this issue:
Affects: fedora-all [bug 1333388]
---
Created mingw-gcc tracking bugs for this issue:
Affects: epel-all [bug 1333389]
---
Statement:
Red Hat Product Security has rated this issue as having
http://www.openwall.com/lists/oss-security/2016/05/05/5http://www.securityfocus.com/bid/90103https://gcc.gnu.org/bugzilla/show_bug.cgi?id=69687https://www.exploit-db.com/exploits/42386/http://www.openwall.com/lists/oss-security/2016/05/05/5http://www.securityfocus.com/bid/90103https://gcc.gnu.org/bugzilla/show_bug.cgi?id=69687https://www.exploit-db.com/exploits/42386/
2017-02-24
Published