5
CVSSv2

CVE-2012-3509

Published: 05/09/2012 Updated: 29/08/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Multiple integer overflows in the (1) _objalloc_alloc function in objalloc.c and (2) objalloc_alloc macro in include/objalloc.h in GNU libiberty, as used by binutils 2.22, allow remote malicious users to cause a denial of service (crash) via vectors related to the "addition of CHUNK_HEADER_SIZE to the length," which triggers a heap-based buffer overflow.

Vulnerable Product Search on Vulmon Subscribe to Product

gnu libiberty -

gnu binutils 2.22

canonical ubuntu linux 14.10

canonical ubuntu linux 14.04

canonical ubuntu linux 12.04

canonical ubuntu linux 10.04

debian debian linux 7.0

Vendor Advisories

Debian Bug report logs - #688951 binutils: CVE-2012-3509 Package: binutils; Maintainer for binutils is Matthias Klose <doko@debianorg>; Source for binutils is src:binutils (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Thu, 27 Sep 2012 09:36:02 UTC Severity: important Tags: patch, secu ...
Applications from GNU binutils could be made to crash, run programs, or delete arbitrary files as your login if they opened a specially crafted file ...