CVE-2005-4807
Summary
| CVE | CVE-2005-4807 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2005-12-31 05:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Stack-based buffer overflow in the as_bad function in messages.c in the GNU as (gas) assembler in Free Software Foundation GNU Binutils before 20050721 allows attackers to execute arbitrary code via a .c file with crafted inline assembly code. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Canonical | Ubuntu Linux | 5.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 5.10 | All | All | All |
| Application | Gnu | Binutils | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Bug 99464 – sys-devel/binutils: buffer overflow in gas | af854a3a-2127-422b-91ae-364da2661108 | bugs.gentoo.org | Patch, Third Party Advisory |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | Permissions Required |
| Ubuntu update for binutils - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Patch, Third Party Advisory |
| www.osvdb.org/27960 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | Broken Link |
| GNU BinUtils GAS Buffer Overflow Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Exploit, Patch, Third Party Advisory, VDB Entry |
| usn/usn-336-1 - Ubuntu: Linux for human beings | af854a3a-2127-422b-91ae-364da2661108 | www.ubuntu.com | Patch, Third Party Advisory |
| GNU Binutils assembler Buffer Overflow Vulnerability - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Patch, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2006-08-24 | Mark J Cox | gas (and gcc) make no promise that they are fault tolerant to bad input. We do not plan on producing security updates for Red Hat Enterprise Linux to correct these bugs. |
There are currently no legacy QID mappings associated with this CVE.