PublicDate: 2006-05-15 16:06:00 UTC Candidate: CVE-2006-2362 References: https://ubuntu.com/security/notices/USN-292-1 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2362 Description: Buffer overflow in getsym in tekhex.c in libbfd in Free Software Foundation GNU Binutils before 20060423, as used by GNU strings, allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a file with a crafted Tektronix Hex Format (TekHex) record in which the length character is not a valid hexadecimal character. Ubuntu-Description: Notes: Priority: untriaged Discovered-by: Assigned-to: CVSS: Bugs: dapper_binutils: released (2.16.1cvs20060117-1ubuntu2.1) edgy_binutils: released (2.17-1ubuntu1) feisty_binutils: released (2.17-1ubuntu1) devel_binutils: released (2.17-1ubuntu1) upstream_binutils: needs-triage