PT-2017-4296 · Gnu+1 · Gnu Binutils+1
Skysider
·
Publicado
2017-09-23
·
Atualizado
2021-07-21
·
CVE-2017-14930
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions:
GNU Binutils version 2.29 and earlier
Description:
The issue is related to a memory leak in the
decode line info function in the dwarf2.c component of the Binary File Descriptor (BFD) library, also known as libbfd. This allows remote attackers to cause a denial of service by consuming memory via a crafted ELF file. The memory leak occurs due to a resource not being released after its valid usage period has expired.Recommendations:
For GNU Binutils version 2.29 and earlier, consider updating to a newer version that contains a fix for this issue.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
Missing Release of Resource after Effective Lifetime
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Gnu Binutils
Ubuntu