LOW · 3.6

CVE-2014-8737

Multiple directory traversal vulnerabilities in GNU binutils 2.24 and earlier allow local users to delete arbitrary files via a .. (dot dot) or full path name in an archive to (1) strip or (2) objcopy...

Vulnerability Description

Multiple directory traversal vulnerabilities in GNU binutils 2.24 and earlier allow local users to delete arbitrary files via a .. (dot dot) or full path name in an archive to (1) strip or (2) objcopy or create arbitrary files via (3) a .. (dot dot) or full path name in an archive to ar.

CVSS Score

3.6

LOW

AV:L/AC:L/Au:N/C:N/I:P/A:P
Confidentiality
NONE
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
CanonicalUbuntu Linux10.04
GnuBinutils<= 2.24
FedoraprojectFedora19

Related Weaknesses (CWE)

References

FAQ

What is CVE-2014-8737?

CVE-2014-8737 is a vulnerability with a CVSS score of 3.6 (LOW). Multiple directory traversal vulnerabilities in GNU binutils 2.24 and earlier allow local users to delete arbitrary files via a .. (dot dot) or full path name in an archive to (1) strip or (2) objcopy...

How severe is CVE-2014-8737?

CVE-2014-8737 has been rated LOW with a CVSS base score of 3.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-8737?

Check the references section above for vendor advisories and patch information. Affected products include: Canonical Ubuntu Linux, Gnu Binutils, Fedoraproject Fedora.