CVE-2014-8503: Buffer Overflow
Last updated 24 July 2024
Other sources
Stack overflow was reported [1] in objdump when parsing a crafted ihex file [2]. Upstream patch is at [3].
[1]: https://sourceware.org/bugzilla/showbug.cgi?id=17512#c33 [2]: https://sourceware.org/bugzilla/attachment.cgi?id=7869 [3]: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=0102ea8cec5fc509bba6c91df61b7ce23a799d32
— Red Hat
Stack-based buffer overflow in the ihexscan function in bfd/ihex.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly have other unspecified impact via a crafted ihex file.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2014-8503?
CVE-2014-8503 refers to a stack-based buffer overflow vulnerability in the ihex_scan function in GNU binutils 2.24 and earlier versions.
What is the severity of CVE-2014-8503?
CVE-2014-8503 has a severity rating of low.
How does CVE-2014-8503 impact systems?
CVE-2014-8503 allows remote attackers to cause a denial of service (crash) and potentially have other unspecified impacts by exploiting a crafted ihex file.
Which software versions are affected by CVE-2014-8503?
GNU binutils 2.24 and earlier versions are affected by CVE-2014-8503.
Where can I find more information about CVE-2014-8503?
You can find more information about CVE-2014-8503 at the following references: [1] http://www.openwall.com/lists/oss-security/2014/10/31/1, [2] https://bugzilla.redhat.com/show_bug.cgi?id=1162607, [3] https://sourceware.org/bugzilla/show_bug.cgi?id=17512