PT-2017-14297 · Gnu+2 · Gnu Binutils+2
Agostino Sarubbo
·
Published
2017-10-27
·
Updated
2024-06-15
·
CVE-2017-15939
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
GNU Binutils version 2.29
Description
The issue is related to the handling of NULL files in a .debug line file table in the Binary File Descriptor (BFD) library, which can cause a denial of service due to a NULL pointer dereference and application crash when processing a crafted ELF file. This is related to the
concat filename function.Recommendations
For GNU Binutils version 2.29, consider updating to a newer version that includes a complete fix for this issue, as the current version contains an incomplete fix.
Fix
DoS
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gnu Binutils
Suse
Ubuntu