CVE-2014-8737

GNU binutils <2.24 - Path Traversal

Title source: llm

Description

Multiple directory traversal vulnerabilities in GNU binutils 2.24 and earlier allow local users to delete arbitrary files via a .. (dot dot) or full path name in an archive to (1) strip or (2) objcopy or create arbitrary files via (3) a .. (dot dot) or full path name in an archive to ar.

References (19)

Scores

EPSS 0.0006
EPSS Percentile 19.3%

Classification

CWE
CWE-22
Status draft

Affected Products (8)

canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
gnu/binutils < 2.24
fedoraproject/fedora
fedoraproject/fedora
fedoraproject/fedora

Timeline

Published Dec 09, 2014
Tracked Since Feb 18, 2026