Multiple directory traversal vulnerabilities in GNU binutils 2.24 and earlier allow local users to delete arbitrary files via a .. (dot dot) or full path name in an archive to (1) strip or (2) objcopy or create arbitrary files via (3) a .. (dot dot) or full path name in an archive to ar.
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "binutils",
"binary_version": "2.24-5ubuntu3.1"
},
{
"binary_name": "binutils-dev",
"binary_version": "2.24-5ubuntu3.1"
},
{
"binary_name": "binutils-multiarch",
"binary_version": "2.24-5ubuntu3.1"
},
{
"binary_name": "binutils-multiarch-dev",
"binary_version": "2.24-5ubuntu3.1"
},
{
"binary_name": "binutils-source",
"binary_version": "2.24-5ubuntu3.1"
},
{
"binary_name": "binutils-static",
"binary_version": "2.24-5ubuntu3.1"
}
]
}