A buffer overflow vulnerability was discovered in objdump, a program for displaying information from object files. The vulnerability is caused by a lack of proper bounds checking when processing certain instructions, which can lead to a global buffer overflow. The command used to trigger the vulnerability was `objdump -D <file>`.
A global buffer overflow vulnerability was discovered in objdump when fuzzing with American Fuzzy Lop and AddressSanitizer. The command used was `objdump -D <file>` and the minimized file causing the issue and the ASAN report log were attached. The reduced stacktrace with links to the corresponding source lines on a GitHub mirror was provided.
A stack-buffer-overflow vulnerability was discovered in objdump when fuzzing with American Fuzzy Lop and AddressSanitizer. The command used was `objdump -D <file>` and the compilation flags used were `-g -O2 -fno-omit-frame-pointer -fsanitize=address -fno-sanitize-recover=undefined` with configuration settings `--enable-targets=all --disable-shared`.
A global buffer overflow vulnerability was discovered in decode_pseudodbg_assert_0 at opcodes/bfin-dis.c:4604 when fuzzing objdump with American Fuzzy Lop and AddressSanitizer. The command used was `objdump -D <file>`.
A stack-buffer-overflow vulnerability was discovered in bfd_get_string in bfd/ieee.c. The vulnerability occurs when a maliciously crafted input is passed to the function, which can lead to a buffer overflow. The command used to trigger the vulnerability was `objdump -D <file>`, which was fuzzed with American Fuzzy Lop and AddressSanitizer.
I have been fuzzing objdump with American Fuzzy Lop and AddressSanitizer. The command I used was `objdump -D <file>`. Error in "disassemble_bytes": heap-buffer-overflow in disassemble_bytes at binutils/objdump.c:1993 (see https://github.com/bminor/binutils-gdb/blob/561bf3e950e410fbcac06523d43039f1f58150ca/binutils/objdump.c#L1993) in disassemble_section at binutils/objdump.c:2309 (see https://github.com/bminor/binutils-gdb/blob/561bf3e950e410fbcac06523d43039f1f58150ca/binutils/objdump.c#L2309) in bfd_map_over_sections at bfd/section.c:1395 (see https://github.com/bminor/binutils-gdb/blob/561bf3e950e410fbcac06523d43039f1f58150ca/bfd/section.c#L1395) in disassemble_data at binutils/objdump.c:2445 (see https://github.com/bminor/binutils-gdb/blob/561bf3e950e410fbcac06523d43039f1f58150ca/binutils/objdump.c#L2445) in dump_bfd at binutils/objdump.c:3547 (see https://github.com/bminor/binutils-gdb/blob/561bf3e950e410fbcac06523d43039f1f58150ca/binutils/objdump.c#L3547) in display_file at binutils/objdump.c:3714 (see https://github.com/bminor/binutils-gdb/blob/561bf3e950e410fbcac06523d43039f1f58150ca/binutils/objdump.c#L3714) in main at binutils/objdump.c:4016 (see https://github.com/bminor/binutils-gdb/blob/561bf3e950e410fbcac06523d43039f1f58150ca/binutils/objdump.c#L4016)
The vulnerability exist in the web interface, which is accessible without authentication. Once modified, systems use foreign DNS servers, which are usually set up by cybercriminals. Users with vulnerable systems or devices who try to access certain sites are instead redirected to possibly malicious sites. Modifying systems' DNS settings allows cybercriminals to perform malicious activities like steering unknowing users to bad sites, replacing ads on legitimate sites, controlling and redirecting network traffic, and pushing additional malware.
The vulnerability exist in the web interface, which is accessible without authentication. Once modified, systems use foreign DNS servers, which are usually set up by cybercriminals. Users with vulnerable systems or devices who try to access certain sites are instead redirected to possibly malicious sites. Modifying systems' DNS settings allows cybercriminals to perform malicious activities like steering unknowing users to bad sites, replacing ads on legitimate sites, controlling and redirecting network traffic, and pushing additional malware.
The vulnerability exist in the web interface, which is accessible without authentication. Once modified, systems use foreign DNS servers, which are usually set up by cybercriminals. Users with vulnerable systems or devices who try to access certain sites are instead redirected to possibly malicious sites. Modifying systems' DNS settings allows cybercriminals to perform malicious activities like steering unknowing users to bad sites, replacing ads on legitimate sites, controlling and redirecting network traffic, and pushing additional malware.
The vulnerability exist in the web interface, which is accessible without authentication. Once modified, systems use foreign DNS servers, which are usually set up by cybercriminals. Users with vulnerable systems or devices who try to access certain sites are instead redirected to possibly malicious sites. Modifying systems' DNS settings allows cybercriminals to perform malicious activities like steering unknowing users to bad sites, replacing ads on legitimate sites, controlling and redirecting network traffic, and pushing additional malware.