CVE-2012-3509

Published: 05 September 2012

Multiple integer overflows in the (1) _objalloc_alloc function in objalloc.c and (2) objalloc_alloc macro in include/objalloc.h in GNU libiberty, as used by binutils 2.22, allow remote attackers to cause a denial of service (crash) via vectors related to the "addition of CHUNK_HEADER_SIZE to the length," which triggers a heap-based buffer overflow.

Priority

Low

Status

Package Release Status
binutils
Launchpad, Ubuntu, Debian
Upstream Needs triage

Ubuntu 14.04 ESM (Trusty Tahr) Not vulnerable
(2.24-5ubuntu3)
Patches:
Upstream: http://gcc.gnu.org/ml/gcc-patches/2012-08/msg01986.html
Upstream: https://gcc.gnu.org/viewcvs/gcc?view=revision&revision=191413