PT-2017-4278 · Gnu+3 · Gnu Binutils+3
Ned Williamson
·
Published
2017-07-21
·
Updated
2024-06-15
·
CVE-2017-12456
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
GNU Binutils versions 2.29 and earlier
Description:
The issue is related to the
read symbol stabs debugging info function in the rddbg.c component of GNU Binutils, which is associated with reading beyond the boundaries of a data buffer. This can be exploited by a remote attacker to access confidential data, compromise data integrity, and cause a denial of service.Recommendations:
For GNU Binutils versions 2.29 and earlier, consider updating to a newer version to mitigate the risk of exploitation. As a temporary workaround, restrict the use of the
read symbol stabs debugging info function in the rddbg.c component until a patch is available. Avoid processing crafted binary files with the affected function until the issue is resolved.Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Gnu Binutils
Suse
Ubuntu