GNU Binutils Binary File Descriptor Library Integer Overflow Vulnerability
BID:13830
Info
GNU Binutils Binary File Descriptor Library Integer Overflow Vulnerability
| Bugtraq ID: | 13830 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 01 2005 12:00AM |
| Updated: | Jun 01 2005 12:00AM |
| Credit: | Discovery of this issue is credited to Tavis Ormandy and Ned Ludd of the Gentoo Linux Security Audit Team. |
| Vulnerable: |
GNU Binutils 2.15 GNU Binutils 2.14 Gentoo Linux |
| Not Vulnerable: | |
Discussion
GNU Binutils Binary File Descriptor Library Integer Overflow Vulnerability
The GNU Binutils Binary File Descriptor Library is prone to an integer overflow vulnerability.
This vulnerability manifests when a tool that is linked to the affected library is used to process a malicious binary. If a binary is sufficient to trigger the issue, attacker-supplied code may be executed in the context of the user that is running the vulnerable utility.
GNU Binutils up to version 2.16-r1 are affected.
The GNU Binutils Binary File Descriptor Library is prone to an integer overflow vulnerability.
This vulnerability manifests when a tool that is linked to the affected library is used to process a malicious binary. If a binary is sufficient to trigger the issue, attacker-supplied code may be executed in the context of the user that is running the vulnerable utility.
GNU Binutils up to version 2.16-r1 are affected.
Exploit / POC
GNU Binutils Binary File Descriptor Library Integer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
GNU Binutils Binary File Descriptor Library Integer Overflow Vulnerability
Solution:
Gentoo has released an advisory (GLSA 200506-01) and an updated eBuild to address this vulnerability. Gentoo users that are running the affected software may apply the update by issuing the following sequence of commands as a superuser:
emerge --sync
emerge --ask --oneshot --verbose sys-devel/binutils
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Gentoo has released an advisory (GLSA 200506-01) and an updated eBuild to address this vulnerability. Gentoo users that are running the affected software may apply the update by issuing the following sequence of commands as a superuser:
emerge --sync
emerge --ask --oneshot --verbose sys-devel/binutils
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
GNU Binutils Binary File Descriptor Library Integer Overflow Vulnerability
References:
References:
- Vendor Homepage (Sony)