PT-2017-4298 · Gnu · Gnu Binutils

Published

2017-09-26

·

Updated

2019-10-03

·

CVE-2017-14933

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: GNU Binutils version 2.29
Description: The issue is related to the read formatted entries function in the dwarf2.c component of GNU Binutils. It involves an infinite loop due to an unreachable exit condition. This can be exploited by a remote attacker using a specially crafted ELF file, leading to a denial of service.
Recommendations: For GNU Binutils version 2.29, consider disabling the read formatted entries function in the dwarf2.c component as a temporary workaround until a patch is available. Restrict access to the dwarf2.c component to minimize the risk of exploitation. Avoid using specially crafted ELF files with the affected read formatted entries function until the issue is resolved.

Fix

Infinite Loop

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-07753
CVE-2017-14933

Affected Products

Gnu Binutils