binutils 'peXXigen.c' Remote Denial of Service Vulnerability
BID:70866
Info
binutils 'peXXigen.c' Remote Denial of Service Vulnerability
| Bugtraq ID: | 70866 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-8501 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 31 2014 12:00AM |
| Updated: | Jul 26 2017 07:08PM |
| Credit: | Michal Zalewski |
| Vulnerable: |
Ubuntu Ubuntu Linux 17.04 Ubuntu Ubuntu Linux 16.04 LTS Ubuntu Ubuntu Linux 14.10 Ubuntu Ubuntu Linux 14.04 LTS Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 ARM Ubuntu Ubuntu Linux 10.04 amd64 Oracle Linux 0 Oracle Enterprise Linux 7 Mandriva Business Server 1 X86 64 Mandriva Business Server 1 IBM PowerKVM 3.1 IBM PowerKVM 2.1 Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 binutils binutils 2.24 |
| Not Vulnerable: | |
Discussion
binutils 'peXXigen.c' Remote Denial of Service Vulnerability
binutils is prone to a remote denial-of-service vulnerability.
A remote attacker may exploit this issue to crash the application resulting in a denial-of-service condition.
binutils 2.24 is vulnerable; other versions may also be affected.
binutils is prone to a remote denial-of-service vulnerability.
A remote attacker may exploit this issue to crash the application resulting in a denial-of-service condition.
binutils 2.24 is vulnerable; other versions may also be affected.
Exploit / POC
binutils 'peXXigen.c' Remote Denial of Service Vulnerability
An attacker can exploit this issue using readily available tools.
An attacker can exploit this issue using readily available tools.
Solution / Fix
binutils 'peXXigen.c' Remote Denial of Service Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Mandriva Business Server 1 X86 64
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Mandriva Business Server 1 X86 64
-
Mandriva binutils-2.22-4.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/ -
Mandriva lib64binutils-devel-2.22-4.1.mbs1.x86_64.rpm
http://www.mandriva.com/en/downloads/
References
binutils 'peXXigen.c' Remote Denial of Service Vulnerability
References:
References:
- binutils Homepage (binutils)
- Bug 17512 - segfault in PE parser / _bfd_pei_swap_aouthdr_in (Sourceware)
- Fix a seg-fault in strings and other binutuils when parsing a corrupt PE (Sourceware)
- isg3T1023355 : Multiple vulnerabilities in Gnu binutils affect PowerKVM (IBM)
- Ref: linuxbulletinoct2015-2719645 Oracle Linux Bulletin - October 2015 Revision (Oracle)