PT-2017-14297 · Gnu+2 · Gnu Binutils+2

Agostino Sarubbo

·

Publicado

2017-10-27

·

Atualizado

2024-06-15

·

CVE-2017-15939

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions GNU Binutils version 2.29
Description The issue is related to the handling of NULL files in a .debug line file table in the Binary File Descriptor (BFD) library, which can cause a denial of service due to a NULL pointer dereference and application crash when processing a crafted ELF file. This is related to the concat filename function.
Recommendations For GNU Binutils version 2.29, consider updating to a newer version that includes a complete fix for this issue, as the current version contains an incomplete fix.

Correção

DoS

NULL Pointer Dereference

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-15939
MGASA-2019-0169
OPENSUSE-SU-2018_3223-1
OPENSUSE-SU-2018_3323-1
OPENSUSE-SU-2024:10651-1
SUSE-SU-2018:3170-1
SUSE-SU-2018:3207-1
SUSE-SU-2018:3207-2
USN-4336-2

Produtos afetados

Gnu Binutils
Suse
Ubuntu