"value":"Buffer overflow in getsym in tekhex.c in libbfd in Free Software Foundation GNU Binutils before 20060423, as used by GNU strings, allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a file with a crafted Tektronix Hex Format (TekHex) record in which the length character is not a valid hexadecimal character."
}
]
},
"problemtype":{
"problemtype_data":[
{
"description":[
{
"lang":"eng",
"value":"n/a"
}
]
}
]
},
"references":{
"reference_data":[
{
"name":"20188",
"refsource":"SECUNIA",
"url":"http://secunia.com/advisories/20188"
},
{
"name":"20550",
"refsource":"SECUNIA",
"url":"http://secunia.com/advisories/20550"
},
{
"name":"22932",
"refsource":"SECUNIA",
"url":"http://secunia.com/advisories/22932"
},
{
"name":"27441",
"refsource":"SECUNIA",
"url":"http://secunia.com/advisories/27441"
},
{
"name":"2006-0034",
"refsource":"TRUSTIX",
"url":"http://www.trustix.org/errata/2006/0034/"
},
{
"name":"17950",
"refsource":"BID",
"url":"http://www.securityfocus.com/bid/17950"
},
{
"name":"[bug-binutils] 20060418 [Bug binutils/2584] New: SIGSEGV in strings tool when the file is crafted.",