PT-2017-4298 · Gnu · Gnu Binutils

Publicado

2017-09-26

·

Atualizado

2019-10-03

·

CVE-2017-14933

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: GNU Binutils version 2.29
Description: The issue is related to the read formatted entries function in the dwarf2.c component of GNU Binutils. It involves an infinite loop due to an unreachable exit condition. This can be exploited by a remote attacker using a specially crafted ELF file, leading to a denial of service.
Recommendations: For GNU Binutils version 2.29, consider disabling the read formatted entries function in the dwarf2.c component as a temporary workaround until a patch is available. Restrict access to the dwarf2.c component to minimize the risk of exploitation. Avoid using specially crafted ELF files with the affected read formatted entries function until the issue is resolved.

Correção

Infinite Loop

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-07753
CVE-2017-14933

Produtos afetados

Gnu Binutils