PT-2017-18316 · Gnu+2 · Gnu Binutils+2
Manh-Dung Nguyen
+2
·
Published
2017-05-01
·
Updated
2021-07-21
·
CVE-2017-8395
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
GNU Binutils version 2.28
Description
The Binary File Descriptor (BFD) library is vulnerable due to a missing malloc() return-value check in the bfd generic get section contents function, causing an invalid write of size 8. This issue affects programs that analyze binary programs using the libbfd library, such as objcopy, leading to crashes.
Recommendations
For GNU Binutils version 2.28, consider applying a patch that adds a malloc() return-value check to the bfd generic get section contents function to prevent invalid writes and subsequent crashes.
Fix
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gnu Binutils
Suse
Ubuntu