← Vulnerability feed

Vulnerability record · CVE-2006-2362 · published 15 May 2006

CVE-2006-2362: Gnu binutils out-of-bounds write vulnerability

Gnu · Binutils

Buffer overflow in getsym in tekhex.c in libbfd in Free Software Foundation GNU Binutils before 20060423, as used by GNU strings, allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a file with a crafted Tektronix Hex Format (TekHex) record in which the length character is not a valid hexadecimal character.

7.3 CVSS 3.1 High EPSS 14% · top 3.5% CWE-787 · Out-of-bounds write
7.3CVSS 3.1 base score, v2 7.5
14%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
32References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

Buffer overflow in getsym in tekhex.c in libbfd in Free Software Foundation GNU Binutils before 20060423, as used by GNU strings, allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a file with a crafted Tektronix Hex Format (TekHex) record in which the length character is not a valid hexadecimal character.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://lists.apple.com/archives/security-announce/2007/Oct/msg00001.html Mailing ListThird Party Advisory
http://secunia.com/advisories/20188 Third Party Advisory
http://secunia.com/advisories/20531 Third Party Advisory
http://secunia.com/advisories/20550 Third Party Advisory
http://secunia.com/advisories/22932 Third Party Advisory
http://secunia.com/advisories/27441 Third Party Advisory
http://sourceware.org/bugzilla/show_bug.cgi?id=2584 ExploitIssue TrackingThird Party Advisory
http://www.mail-archive.com/bug-binutils%40gnu.org/msg01516.html Issue TrackingMailing List
http://www.novell.com/linux/security/advisories/2006_26_sr.html Third Party Advisory
http://www.securityfocus.com/bid/17950 ExploitPatchThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id?1018872 Third Party AdvisoryVDB Entry
http://www.trustix.org/errata/2006/0034/ Broken Link
http://www.ubuntu.com/usn/usn-292-1 Broken Link
http://www.vupen.com/english/advisories/2006/1924 Permissions Required
http://www.vupen.com/english/advisories/2007/3665 Permissions Required
https://exchange.xforce.ibmcloud.com/vulnerabilities/26644 Third Party AdvisoryVDB Entry
http://lists.apple.com/archives/security-announce/2007/Oct/msg00001.html Mailing ListThird Party Advisory
http://secunia.com/advisories/20188 Third Party Advisory
http://secunia.com/advisories/20531 Third Party Advisory
http://secunia.com/advisories/20550 Third Party Advisory
http://secunia.com/advisories/22932 Third Party Advisory
http://secunia.com/advisories/27441 Third Party Advisory
http://sourceware.org/bugzilla/show_bug.cgi?id=2584 ExploitIssue TrackingThird Party Advisory
http://www.mail-archive.com/bug-binutils%40gnu.org/msg01516.html Issue TrackingMailing List
http://www.novell.com/linux/security/advisories/2006_26_sr.html Third Party Advisory
http://www.securityfocus.com/bid/17950 ExploitPatchThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id?1018872 Third Party AdvisoryVDB Entry
http://www.trustix.org/errata/2006/0034/ Broken Link
http://www.ubuntu.com/usn/usn-292-1 Broken Link
http://www.vupen.com/english/advisories/2006/1924 Permissions Required
http://www.vupen.com/english/advisories/2007/3665 Permissions Required
https://exchange.xforce.ibmcloud.com/vulnerabilities/26644 Third Party AdvisoryVDB Entry

Track CVE-2006-2362 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-12699Gnu binutils out-of-bounds write vulnerabilityfinish_stab in stabs.c in GNU Binutils 2.30 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified o…EPSS 4.5%9.8CVE-2017-7614Gnu binutils null pointer dereference vulnerabilityelflink.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has a "member access within null pointer" un…EPSS 3.8%9.8CVE-2014-9939Gnu binutils memory buffer overflow vulnerabilityihex.c in GNU Binutils before 2.26 contains a stack buffer overflow when printing bad bytes in Intel Hex objects.EPSS 2.3%9.1CVE-2017-7226Gnu binutils out-of-bounds read vulnerabilityThe pe_ILF_object_p function in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to a heap-b…EPSS 2.5%9.1CVE-2017-6969Gnu binutils out-of-bounds read vulnerabilityreadelf in GNU Binutils 2.28 is vulnerable to a heap-based buffer over-read while processing corrupt RL78 binaries. The vulnerability can trigger pro…EPSS 3.7%8.8CVE-2020-19726Gnu binutils uncontrolled resource consumption vulnerabilityAn issue was discovered in binutils libbfd.c 2.36 relating to the auxiliary symbol data allows attackers to read or write to system memory or cause a…EPSS 0.75%7.8CVE-2026-6846Gnu binutils heap-based buffer overflow vulnerabilityA flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Form…EPSS 0.20%7.8CVE-2022-44840Gnu binutils out-of-bounds write vulnerabilityHeap buffer overflow vulnerability in binutils readelf before 2.40 via function find_section_in_set in file readelf.c.EPSS 0.49%

Source: NIST National Vulnerability Database (record CVE-2006-2362), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.