CVE-2014-8504: Buffer Overflow
Last updated 24 July 2024
Other sources
Stack overflow issue was reported [1] in SREC parser in binutils. Upstream patch that fixes this issue is at [2]. Reproducer for this is available at http://lcamtuf.coredump.cx/strings-stack-overflow - just run "strings" utility on that crafted file.
[1]: https://sourceware.org/bugzilla/showbug.cgi?id=17510#c7 [2]: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=708d7d0d11f0f2d776171979aa3479e8e12a38a0
— Red Hat
Stack-based buffer overflow in the srecscan function in bfd/srec.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly have other unspecified impact via a crafted file.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2014-8504?
CVE-2014-8504 is a vulnerability in GNU binutils 2.24 and earlier that allows remote attackers to cause a denial of service (crash) and possibly have other unspecified impact via a crafted file.
How severe is CVE-2014-8504?
CVE-2014-8504 has a severity level of low.
Which software is affected by CVE-2014-8504?
GNU binutils versions 2.24 and earlier are affected by CVE-2014-8504.
How can I fix CVE-2014-8504?
To fix CVE-2014-8504, update GNU binutils to version 2.25 or later.
Where can I find more information about CVE-2014-8504?
You can find more information about CVE-2014-8504 at the following links: [link1], [link2], [link3].