PT-2017-4065 · Gnu+2 · Gnu Binutils+2

Zhihua Yao

·

Published

2017-08-09

·

Updated

2024-06-15

·

CVE-2017-12799

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GNU Binutils version 2.29
Description The issue concerns a buffer overflow in the elf read notes function, located in bfd/elf.c, which can be triggered by a crafted binary file. This can lead to a denial of service, causing the application to crash. Additionally, it may have other unspecified impacts, potentially allowing remote attackers to access or modify confidential data.
Recommendations For GNU Binutils version 2.29, consider disabling the elf read notes function as a temporary workaround until a patch is available. Restrict access to crafted binary files to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-01398
CVE-2017-12799
MGASA-2019-0169
OPENSUSE-SU-2024:10651-1
SUSE-SU-2017:3170-1
USN-4336-2

Affected Products

Gnu Binutils
Suse
Ubuntu