CVE-2014-8502: Buffer Overflow
A heap overflow was reborted [1] when running objdump on a specially crafted PE executable [2]. Upstream patches that address this are at [3] and [4].
[1]: https://sourceware.org/bugzilla/showbug.cgi?id=17512#c17 [2]: https://sourceware.org/bugzilla/attachment.cgi?id=7862 [3]: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=5a4b0ccc20ba30caef53b01bee2c0aaa5b855339 [4]: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=acafeb6056bec47d7211cf462a7c211a8c95cf42
Other sources
Heap-based buffer overflow in the peprintedata function in bfd/peXXigen.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly have other unspecified impact via a truncated export table in a PE file.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2014-8502.
What is the title of this vulnerability?
The title of this vulnerability is "Heap-based buffer overflow in the pe_print_edata function in bfd/peXXigen.c in GNU binutils 2.24 and..."
What is the severity of CVE-2014-8502?
The severity of CVE-2014-8502 is low.
How does CVE-2014-8502 affect the software?
CVE-2014-8502 affects GNU binutils versions 2.24 and earlier.
How can I fix the vulnerability (CVE-2014-8502)?
To fix CVE-2014-8502, update GNU binutils to version 2.25 or later.