{"api_version":"1","generated_at":"2026-07-23T06:03:09+00:00","cve":"CVE-2005-4807","urls":{"html":"https://cve.report/CVE-2005-4807","api":"https://cve.report/api/cve/CVE-2005-4807.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-4807","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-4807"},"summary":{"title":"CVE-2005-4807","description":"Stack-based buffer overflow in the as_bad function in messages.c in the GNU as (gas) assembler in Free Software Foundation GNU Binutils before 20050721 allows attackers to execute arbitrary code via a .c file with crafted inline assembly code.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-12-31 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["CWE-119","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://bugs.gentoo.org/show_bug.cgi?id=99464","name":"http://bugs.gentoo.org/show_bug.cgi?id=99464","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"],"title":"Bug 99464 – sys-devel/binutils: buffer overflow in gas","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2006/3307","name":"http://www.vupen.com/english/advisories/2006/3307","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Permissions Required"],"title":"Webmail - OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/21530","name":"http://secunia.com/advisories/21530","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"],"title":"Ubuntu update for binutils - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/27960","name":"http://www.osvdb.org/27960","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.securityfocus.com/bid/19555","name":"http://www.securityfocus.com/bid/19555","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Patch","Third Party Advisory","VDB Entry"],"title":"GNU BinUtils GAS Buffer Overflow Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.ubuntu.com/usn/usn-336-1","name":"http://www.ubuntu.com/usn/usn-336-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"],"title":"usn/usn-336-1 - Ubuntu: Linux for human beings","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/21508","name":"http://secunia.com/advisories/21508","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"],"title":"GNU Binutils assembler Buffer Overflow Vulnerability - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-4807","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-4807","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"4807","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"canonical","cpe5":"ubuntu_linux","cpe6":"5.04","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"4807","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"canonical","cpe5":"ubuntu_linux","cpe6":"5.10","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"4807","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"gnu","cpe5":"binutils","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[{"cvename":"CVE-2005-4807","organization":"Red Hat","lastmodified":"2006-08-24","contributor":"Mark J Cox","statementText":"gas (and gcc) make no promise that they are fault tolerant to bad input. We do not plan on producing security updates for Red Hat Enterprise Linux to correct these bugs.","cve_year":"2005","cve_id":"4807","crc32":"91c75be6"}],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T00:01:23.541Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"27960","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/27960"},{"name":"USN-336-1","tags":["vendor-advisory","x_refsource_UBUNTU","x_transferred"],"url":"http://www.ubuntu.com/usn/usn-336-1"},{"name":"21508","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/21508"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://bugs.gentoo.org/show_bug.cgi?id=99464"},{"name":"19555","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/19555"},{"name":"ADV-2006-3307","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2006/3307"},{"name":"21530","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/21530"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-07-21T00:00:00.000Z","descriptions":[{"lang":"en","value":"Stack-based buffer overflow in the as_bad function in messages.c in the GNU as (gas) assembler in Free Software Foundation GNU Binutils before 20050721 allows attackers to execute arbitrary code via a .c file with crafted inline assembly code."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2006-09-02T09:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"27960","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/27960"},{"name":"USN-336-1","tags":["vendor-advisory","x_refsource_UBUNTU"],"url":"http://www.ubuntu.com/usn/usn-336-1"},{"name":"21508","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/21508"},{"tags":["x_refsource_MISC"],"url":"http://bugs.gentoo.org/show_bug.cgi?id=99464"},{"name":"19555","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/19555"},{"name":"ADV-2006-3307","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2006/3307"},{"name":"21530","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/21530"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-4807","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Stack-based buffer overflow in the as_bad function in messages.c in the GNU as (gas) assembler in Free Software Foundation GNU Binutils before 20050721 allows attackers to execute arbitrary code via a .c file with crafted inline assembly code."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"27960","refsource":"OSVDB","url":"http://www.osvdb.org/27960"},{"name":"USN-336-1","refsource":"UBUNTU","url":"http://www.ubuntu.com/usn/usn-336-1"},{"name":"21508","refsource":"SECUNIA","url":"http://secunia.com/advisories/21508"},{"name":"http://bugs.gentoo.org/show_bug.cgi?id=99464","refsource":"MISC","url":"http://bugs.gentoo.org/show_bug.cgi?id=99464"},{"name":"19555","refsource":"BID","url":"http://www.securityfocus.com/bid/19555"},{"name":"ADV-2006-3307","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/3307"},{"name":"21530","refsource":"SECUNIA","url":"http://secunia.com/advisories/21530"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-4807","datePublished":"2006-08-18T19:55:00.000Z","dateReserved":"2006-08-18T00:00:00.000Z","dateUpdated":"2024-08-08T00:01:23.541Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-12-31 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["CWE-119","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gnu:binutils:*:*:*:*:*:*:*:*","versionEndExcluding":"2.17","matchCriteriaId":"133521B0-6212-48E3-B114-216F626E1D23"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:5.04:*:*:*:*:*:*:*","matchCriteriaId":"42E47538-08EE-4DC1-AC17-883C44CF77BB"},{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:5.10:*:*:*:*:*:*:*","matchCriteriaId":"0FA3A32E-445A-4D39-A8D5-75F5370AD23D"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"4807","Ordinal":"1","Title":"CVE-2005-4807","CVE":"CVE-2005-4807","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"4807","Ordinal":"1","NoteData":"Stack-based buffer overflow in the as_bad function in messages.c in the GNU as (gas) assembler in Free Software Foundation GNU Binutils before 20050721 allows attackers to execute arbitrary code via a .c file with crafted inline assembly code.","Type":"Description","Title":"CVE-2005-4807"},{"CveYear":"2005","CveId":"4807","Ordinal":"2","NoteData":"2006-08-18","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"4807","Ordinal":"3","NoteData":"2006-09-02","Type":"Other","Title":"Modified"}]}}}