CVE-2012-3509: Buffer Overflow
Last updated 24 July 2024
Other sources
Multiple integer overflows in the (1) objallocalloc function in objalloc.c and (2) objallocalloc macro in include/objalloc.h in GNU libiberty, as used by binutils 2.22, allow remote attackers to cause a denial of service (crash) via vectors related to the "addition of CHUNKHEADERSIZE to the length," which triggers a heap-based buffer overflow.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2012-3509?
CVE-2012-3509 is a vulnerability in GNU libiberty that allows remote attackers to cause a denial of service (crash) by exploiting multiple integer overflows.
How does CVE-2012-3509 impact binutils?
CVE-2012-3509 affects binutils 2.22, causing a denial of service (crash) when certain vectors related to the addition of CHUNK_HEADER_SIZE to the len parameter are exploited.
Which versions of binutils are affected by CVE-2012-3509?
Binutils 2.22 is affected by CVE-2012-3509.
How can I fix CVE-2012-3509?
To fix CVE-2012-3509, update binutils to version 2.22-6ubuntu1.2 or later.
Are there any additional references for CVE-2012-3509?
Yes, you can find additional information about CVE-2012-3509 at the following references: http://gcc.gnu.org/bugzilla/show_bug.cgi?id=54411, http://security-tracker.debian.org/tracker/CVE-2012-3509, http://www.securityfocus.com/bid/55281.