CVE-2006-2362

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
15/05/2006
Last modified:
03/04/2025

Description

Buffer overflow in getsym in tekhex.c in libbfd in Free Software Foundation GNU Binutils before 20060423, as used by GNU strings, allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a file with a crafted Tektronix Hex Format (TekHex) record in which the length character is not a valid hexadecimal character.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gnu:binutils:*:*:*:*:*:*:*:* 2.17 (excluding)


References to Advisories, Solutions, and Tools