Wind River Support Network

HomeDefectsLIN7-2439
Fixed

LIN7-2439 : Security Advisory - binutils - CVE-2014-8737

Created: Dec 14, 2014    Updated: Sep 8, 2018
Resolved Date: May 5, 2015
Found In Version: 7.0
Fix Version: 7.0.0.6
Severity: Standard
Applicable for: Wind River Linux 7
Component/s: Userspace

Description

Multiple directory traversal vulnerabilities in GNU binutils 2.24 and earlier allow local users to delete arbitrary files via a .. (dot dot) or full path name in an archive to (1) strip or (2) objcopy or create arbitrary files via (3) a .. (dot dot) or full path name in an archive to ar.

http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-8737

Other Downloads


CVEs


Live chat
Online