Vulnerability Details CVE-2006-2362
Buffer overflow in getsym in tekhex.c in libbfd in Free Software Foundation GNU Binutils before 20060423, as used by GNU strings, allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a file with a crafted Tektronix Hex Format (TekHex) record in which the length character is not a valid hexadecimal character.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.055
EPSS Ranking 89.7%
CVSS Severity
CVSS v3 Score 7.3
CVSS v2 Score 7.5
Products affected by CVE-2006-2362
-
-
cpe:2.3:a:gnu:binutils:2.10
-
cpe:2.3:a:gnu:binutils:2.10.1
-
cpe:2.3:a:gnu:binutils:2.10.1a
-
cpe:2.3:a:gnu:binutils:2.11
-
cpe:2.3:a:gnu:binutils:2.11.1
-
cpe:2.3:a:gnu:binutils:2.11.2
-
cpe:2.3:a:gnu:binutils:2.11.2a
-
cpe:2.3:a:gnu:binutils:2.12
-
cpe:2.3:a:gnu:binutils:2.12.1
-
cpe:2.3:a:gnu:binutils:2.12.1a
-
cpe:2.3:a:gnu:binutils:2.13
-
cpe:2.3:a:gnu:binutils:2.13.1
-
cpe:2.3:a:gnu:binutils:2.13.2
-
cpe:2.3:a:gnu:binutils:2.13.2.1
-
cpe:2.3:a:gnu:binutils:2.13.2.1a
-
cpe:2.3:a:gnu:binutils:2.14
-
cpe:2.3:a:gnu:binutils:2.14a
-
cpe:2.3:a:gnu:binutils:2.15
-
cpe:2.3:a:gnu:binutils:2.15a
-
cpe:2.3:a:gnu:binutils:2.16.1
-
cpe:2.3:a:gnu:binutils:2.16.1a
-
cpe:2.3:a:gnu:binutils:2.6
-
cpe:2.3:a:gnu:binutils:2.7
-
cpe:2.3:a:gnu:binutils:2.8
-
cpe:2.3:a:gnu:binutils:2.8.1
-
cpe:2.3:a:gnu:binutils:2.9
-
cpe:2.3:a:gnu:binutils:2.9.1