Binutils: Multiple vulnerabilities Multiple vulnerabilities were found in Binutils, the worst of which may allow execution of arbitrary code. binutils 2016-12-08 2016-12-08 526626 local, remote 2.25 2.25

The GNU Binutils are a collection of tools to create, modify and analyse binary files. Many of the files use BFD, the Binary File Descriptor library, to do low-level manipulation.

Multiple vulnerabilities have been discovered in Binutils. Please review the CVE identifiers referenced below for details.

A remote attacker could entice a user to open a specially crafted file, possibly resulting in execution of arbitrary code with the privileges of the process, cause a Denial of Service condition, or overwrite arbitrary files.

There is no known workaround at this time.

All Binutils users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=sys-devel/binutils-2.25"
CVE-2014-8484 CVE-2014-8485 CVE-2014-8501 CVE-2014-8502 CVE-2014-8503 CVE-2014-8504 CVE-2014-8737 CVE-2014-8738 whissi whissi