CVE-2014-8484: Buffer Overflow
Last updated 24 July 2024
Other sources
Michal Zalewski reported an invalid read flaw in libbfd, used by, for example, the "strings" utility. Running "strings" on a malicious file could cause "strings" to crash:
http://seclists.org/oss-sec/2014/q4/424
It is unclear yet if it is possible to leverage this issue for more than a crash.
Dave Rutherford noted on oss-security that using certain web browsers to save a malicious file could trigger this issue and cause the browser to crash:
http://seclists.org/oss-sec/2014/q4/426
— Red Hat
The srecscan function in bfd/srec.c in libdbfd in GNU binutils before 2.25 allows remote attackers to cause a denial of service (out-of-bounds read) via a small S-record.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this security issue?
The vulnerability ID for this security issue is CVE-2014-8484.
What is the title of this vulnerability?
The title of this vulnerability is 'srec_scan function in bfd/srec.c in libdbfd in GNU binutils before 2.25 allows remote attackers to cause a denial of service (out-of-bounds read) via a small S-record.'
What is the severity of CVE-2014-8484?
The severity level of CVE-2014-8484 is medium (4).
Which software versions are affected by CVE-2014-8484?
The affected software versions are binutils 2.25 (Ubuntu), binutils 2.20.1-3ubuntu7.2 (Ubuntu), binutils 2.22-6ubuntu1.2 (Ubuntu), binutils 2.24-5ubuntu3.1 (Ubuntu), binutils 2.25 (Red Hat), binutils 2.31.1-16, 2.35.2-2, 2.40-2, 2.41-5 (Debian), binutils-mingw-w64 8.3, 8.11, 10.4, 11+nmu1 (Debian).
How can I fix the vulnerability CVE-2014-8484?
To fix the vulnerability CVE-2014-8484, you should update the affected software to binutils version 2.25 or apply the corresponding patches provided by the vendor.