CVE-2014-8501
Publication date 9 December 2014
Last updated 24 July 2024
Ubuntu priority
The _bfd_XXi_swap_aouthdr_in function in bfd/peXXigen.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (out-of-bounds write) and possibly have other unspecified impact via a crafted NumberOfRvaAndSizes field in the AOUT header in a PE executable.
Status
Package | Ubuntu Release | Status |
---|---|---|
binutils | ||
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty |
Fixed 2.24-5ubuntu3.1
|
|
gdb | ||
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty |
Fixed 7.7.1-0ubuntu5~14.04.3
|
|
Notes
sbeattie
binutils USN description: Hanno Böck discovered that the _bfd_XXi_swap_aouthdr_in function in libbfd in GNU binutils allowed out-of-bounds writes. An attacker could use this to craft input that could cause a denial of service (application crash) or possibly execute arbitrary code.
Patch details
Package | Patch details |
---|---|
binutils |
References
Related Ubuntu Security Notices (USN)
- USN-2496-1
- GNU binutils vulnerabilities
- 9 February 2015
- USN-3367-1
- gdb vulnerabilities
- 26 July 2017