Buffer overflow in Binutils - CVE-2014-8501
Published: December 10, 2014 / Updated: July 28, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
The _bfd_XXi_swap_aouthdr_in function in bfd/peXXigen.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (out-of-bounds write) and possibly have other unspecified impact via a crafted NumberOfRvaAndSizes field in the AOUT header in a PE executable.
Affected software
Amazon Linux AMI
Gentoo Linux
Fedora
binutils (Alpine package)
avr-binutils
mingw-binutils
cross-binutils
cross-gcc
arm-none-eabi-binutils-cs
How to mitigate CVE-2014-8501
avr-binutils - update to 2.24-4.fc21
mingw-binutils - addressed in versions 2.25-1.el7, 2.25-1.fc21
cross-binutils - update to 2.27-9.el7.1
cross-gcc - update to 4.8.5-16.el7.1
arm-none-eabi-binutils-cs - update to 2014.05.28-3.fc21
External References
- http://lists.fedoraproject.org/pipermail/package-announce/2014-December/145262.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-December/145328.html
- http://lists.fedoraproject.org/pipermail/package-announce/2014-December/145742.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-January/147346.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-January/147354.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-January/148427.html
- http://secunia.com/advisories/62241
- http://secunia.com/advisories/62746
- http://www.mandriva.com/security/advisories?name=MDVSA-2015:029
- http://www.openwall.com/lists/oss-security/2014/10/26/3
- http://www.openwall.com/lists/oss-security/2014/10/31/1
- http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
- http://www.securityfocus.com/bid/70866
- http://www.ubuntu.com/usn/USN-2496-1
- https://bugzilla.redhat.com/show_bug.cgi?id=1162570
- https://security.gentoo.org/glsa/201612-24
- https://sourceware.org/bugzilla/show_bug.cgi?id=17512
- https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=7e1e19887abd24aeb15066b141cdff5541e0ec8e
Related Security Bulletins
- Buffer overflow in GNU Binutils
- Buffer overflow in binutils (Alpine package)
- Amazon Linux AMI update for binutils
- Gentoo update for Binutils
- Fedora 21 update for avr-binutils
- Fedora 21 update for arm-none-eabi-binutils-cs
- Fedora EPEL 7 update for mingw-binutils
- Fedora 21 update for mingw-binutils
- Fedora EPEL 7 update for cross-binutils, cross-gcc