PT-2017-4298 · Gnu · Gnu Binutils
Published
2017-09-26
·
Updated
2019-10-03
·
CVE-2017-14933
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions:
GNU Binutils version 2.29
Description:
The issue is related to the
read formatted entries function in the dwarf2.c component of GNU Binutils. It involves an infinite loop due to an unreachable exit condition. This can be exploited by a remote attacker using a specially crafted ELF file, leading to a denial of service.Recommendations:
For GNU Binutils version 2.29, consider disabling the
read formatted entries function in the dwarf2.c component as a temporary workaround until a patch is available. Restrict access to the dwarf2.c component to minimize the risk of exploitation. Avoid using specially crafted ELF files with the affected read formatted entries function until the issue is resolved.Fix
Infinite Loop
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gnu Binutils