The bfdXXiswapaouthdr_in function in bfd/peXXigen.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (out-of-bounds write) and possibly have other unspecified impact via a crafted NumberOfRvaAndSizes field in the AOUT header in a PE executable.
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "binutils",
"binary_version": "2.24-5ubuntu3.1"
},
{
"binary_name": "binutils-dev",
"binary_version": "2.24-5ubuntu3.1"
},
{
"binary_name": "binutils-multiarch",
"binary_version": "2.24-5ubuntu3.1"
},
{
"binary_name": "binutils-multiarch-dev",
"binary_version": "2.24-5ubuntu3.1"
},
{
"binary_name": "binutils-source",
"binary_version": "2.24-5ubuntu3.1"
},
{
"binary_name": "binutils-static",
"binary_version": "2.24-5ubuntu3.1"
}
]
}
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "gdb",
"binary_version": "7.7.1-0ubuntu5~14.04.3"
},
{
"binary_name": "gdb-minimal",
"binary_version": "7.7.1-0ubuntu5~14.04.3"
},
{
"binary_name": "gdb-multiarch",
"binary_version": "7.7.1-0ubuntu5~14.04.3"
},
{
"binary_name": "gdb-source",
"binary_version": "7.7.1-0ubuntu5~14.04.3"
},
{
"binary_name": "gdb64",
"binary_version": "7.7.1-0ubuntu5~14.04.3"
},
{
"binary_name": "gdbserver",
"binary_version": "7.7.1-0ubuntu5~14.04.3"
}
]
}