Multiple directory traversal vulnerabilities in GNU binutils 2.24 and earlier allow local users to delete arbitrary files via a .. (dot dot) or full path name in an archive to (1) strip or (2) objcopy or create arbitrary files via (3) a .. (dot dot) or full path name in an archive to ar.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2014-12-09T22:52:00

Updated: 2024-08-06T13:26:02.580Z

Reserved: 2014-11-13T00:00:00

Link: CVE-2014-8737

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2014-12-09T23:59:07.097

Modified: 2023-11-07T02:22:42.837

Link: CVE-2014-8737

cve-icon Redhat

Severity : Moderate

Publid Date: 2014-11-04T00:00:00Z

Links: CVE-2014-8737 - Bugzilla