Synced 30 Sept 2026 23:45 UTC Account
← All products

CVE-2014-8737

LOW severity · CVSS 3.6 · Path traversal
3.6CVSS LOW

Summary

Multiple directory traversal vulnerabilities in GNU binutils 2.24 and earlier allow local users to delete arbitrary files via a .. (dot dot) or full path name in an archive to (1) strip or (2) objcopy or create arbitrary files via (3) a .. (dot dot) or full path name in an archive to ar.

Impact & exploitability

Attack vectorLocal
Attack complexityLow
Privileges required—
User interaction—
Confidentiality impactNone
Integrity impact—
Availability impact—
Exploit probability (EPSS)1%

AV:L/AC:L/Au:N/C:N/I:P/A:P

Affected products we track (1)

Recommendation

Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.