PT-2017-4304 · Gnu+1 · Gnu Binutils+1

Agostino Sarubbo

·

Publicado

2017-09-25

·

Atualizado

2021-07-21

·

CVE-2017-15020

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: GNU Binutils version 2.29
Description: The issue is related to the dwarf1.c component in the Binary File Descriptor (BFD) library, which mishandles pointers and allows remote attackers to cause a denial of service or possibly have other impacts via a crafted ELF file. This is related to the parse die and parse line table functions, as demonstrated by a heap-based buffer over-read. The exploitation of this issue can allow an attacker to access confidential data, disrupt its integrity, and cause a denial of service using a specially crafted ELF file.
Recommendations: For GNU Binutils version 2.29, consider updating to a newer version that addresses this issue. As a temporary workaround, restrict the use of the dwarf1.c component or the parse die and parse line table functions to minimize the risk of exploitation. Avoid using specially crafted ELF files that could trigger the buffer over-read vulnerability.

Correção

DoS

Out of bounds Read

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-07759
CVE-2017-15020
MGASA-2019-0169
USN-4336-2

Produtos afetados

Gnu Binutils
Ubuntu