[Secure-testing-team] Integer overflow in applications parsing ELF headers

Moritz Muehlenhoff jmm at inutil.org
Wed May 11 11:05:01 UTC 2005


Hi,
It's been discovered that a wide range of applications parsing ELF segment
headers are vulnerable to an integer overflow when allocating memory for
segment headers. Applications already known to be affected are:
binutils
elfutils
gdb
ht (already filed a minute ago)
prelink

Are there other applications inside Debian embedding BFD or parsing ELF
binaries with their own code?

Cheers,
        Moritz




More information about the Secure-testing-team mailing list