binutils 'srec.c' Stack Based Buffer Overflow Vulnerability
BID:70761
Info
binutils 'srec.c' Stack Based Buffer Overflow Vulnerability
| Bugtraq ID: | 70761 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-8504 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 27 2014 12:00AM |
| Updated: | Jul 06 2016 01:37PM |
| Credit: | Michal Zalewski |
| Vulnerable: |
Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 Oracle Linux 0 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 |
| Not Vulnerable: | |
Exploit / POC
binutils 'srec.c' Stack Based Buffer Overflow Vulnerability
An attacker can exploit this issue using readily available tools.
An attacker can exploit this issue using readily available tools.
Solution / Fix
binutils 'srec.c' Stack Based Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Mandriva Business Server 1 X86 64
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Mandriva Business Server 1 X86 64
-
Mandriva binutils-2.22-4.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64binutils-devel-2.22-4.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/
References
binutils 'srec.c' Stack Based Buffer Overflow Vulnerability
References:
References:
- Re: Re: strings / libbfd crasher (Seclist.org)
- GNU Homepage (binutils)
- This patch fixes a flaw in the SREC parser which could cause a stack overflow (Sourceware)
- Bug 17510 - strings: crash when given a truncated ELF (Sourceware)
- Bug 17510 - strings: crash when given a truncated ELF (Sourceware)
- isg3T1023355 : Multiple vulnerabilities in Gnu binutils affect PowerKVM (IBM)
- Ref: linuxbulletinoct2015-2719645 Oracle Linux Bulletin - October 2015 Revision (Oracle)