PT-2017-18313 · Gnu+1 · Gnu Binutils+1

Manh-Dung Nguyen

·

Published

2017-05-01

·

Updated

2024-06-15

·

CVE-2017-8392

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions GNU Binutils version 2.28
Description The Binary File Descriptor library is prone to an invalid read of size 8 due to a missing check for NULL symbols in the bfd dwarf2 find nearest line function. This issue causes programs that analyze binary programs using the library, such as objdump, to crash.
Recommendations For GNU Binutils version 2.28, consider applying a patch that adds a check to determine whether symbols are NULL in the bfd dwarf2 find nearest line function to prevent the invalid read.

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-8392
MGASA-2019-0169
OPENSUSE-SU-2018_3223-1
OPENSUSE-SU-2024:10651-1
SUSE-SU-2017:3170-1
SUSE-SU-2018:3207-1
SUSE-SU-2018:3207-2

Affected Products

Gnu Binutils
Suse