GNU BinUtils GAS Buffer Overflow Vulnerability
BID:19555
Info
GNU BinUtils GAS Buffer Overflow Vulnerability
| Bugtraq ID: | 19555 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2005-4807 CVE-2005-4808 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 17 2006 12:00AM |
| Updated: | Oct 19 2006 06:58PM |
| Credit: | Tavis Ormandy <[email protected]> discovered this vulnerability. |
| Vulnerable: |
Ubuntu Ubuntu Linux 5.10 sparc Ubuntu Ubuntu Linux 5.10 powerpc Ubuntu Ubuntu Linux 5.10 i386 Ubuntu Ubuntu Linux 5.10 amd64 Ubuntu Ubuntu Linux 5.0 4 powerpc Ubuntu Ubuntu Linux 5.0 4 i386 Ubuntu Ubuntu Linux 5.0 4 amd64 Mandriva Linux Mandrake 2006.0 x86_64 Mandriva Linux Mandrake 2006.0 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 GNU Binutils 2.16.1 GNU Binutils 2.15 GNU Binutils 2.14 GNU Binutils 2.12 GNU Binutils 2.11 GNU Binutils 2.16.91.0.2 |
| Not Vulnerable: | |
Discussion
GNU BinUtils GAS Buffer Overflow Vulnerability
GNU binutils GAS (GNU assembler) is prone to a buffer-overflow vulnerability because it fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
Remote attackers may crash the application or execute arbitrary machine code in the context of the application.
GNU binutils GAS (GNU assembler) is prone to a buffer-overflow vulnerability because it fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
Remote attackers may crash the application or execute arbitrary machine code in the context of the application.
Exploit / POC
GNU BinUtils GAS Buffer Overflow Vulnerability
An exploit is available.
An exploit is available.
Solution / Fix
GNU BinUtils GAS Buffer Overflow Vulnerability
Solution:
A patch is available to address this issue:
http://bugs.gentoo.org/attachment.cgi?id=63736http://bugs.gentoo.org/attachment.cgi?id=63736
Please see the referenced third-party advisories for information on obtaining and applying fixes.
GNU Binutils 2.16.91.0.2
Solution:
A patch is available to address this issue:
http://bugs.gentoo.org/attachment.cgi?id=63736http://bugs.gentoo.org/attachment.cgi?id=63736
Please see the referenced third-party advisories for information on obtaining and applying fixes.
GNU Binutils 2.16.91.0.2
-
Mandriva binutils-2.16.91.0.2-3.1.20060mdk.i586.rpm
Mandriva Linux 2006.0:
http://wwwnew.mandriva.com/en/downloads -
Mandriva binutils-2.16.91.0.2-3.1.20060mdk.x86_64.rpm
Mandriva Linux 2006.0:
http://wwwnew.mandriva.com/en/downloads -
Mandriva lib64binutils2-2.16.91.0.2-3.1.20060mdk.x86_64.rpm
Mandriva Linux 2006.0:
http://wwwnew.mandriva.com/en/downloads -
Mandriva lib64binutils2-devel-2.16.91.0.2-3.1.20060mdk.x86_64.rpm
Mandriva Linux 2006.0:
http://wwwnew.mandriva.com/en/downloads -
Mandriva libbinutils2-2.16.91.0.2-3.1.20060mdk.i586.rpm
Mandriva Linux 2006.0:
http://wwwnew.mandriva.com/en/downloads -
Mandriva libbinutils2-devel-2.16.91.0.2-3.1.20060mdk.i586.rpm
Mandriva Linux 2006.0:
http://wwwnew.mandriva.com/en/downloads
References
GNU BinUtils GAS Buffer Overflow Vulnerability
References:
References: