PT-2017-4304 · Gnu+1 · Gnu Binutils+1

Agostino Sarubbo

·

Published

2017-09-25

·

Updated

2021-07-21

·

CVE-2017-15020

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: GNU Binutils version 2.29
Description: The issue is related to the dwarf1.c component in the Binary File Descriptor (BFD) library, which mishandles pointers and allows remote attackers to cause a denial of service or possibly have other impacts via a crafted ELF file. This is related to the parse die and parse line table functions, as demonstrated by a heap-based buffer over-read. The exploitation of this issue can allow an attacker to access confidential data, disrupt its integrity, and cause a denial of service using a specially crafted ELF file.
Recommendations: For GNU Binutils version 2.29, consider updating to a newer version that addresses this issue. As a temporary workaround, restrict the use of the dwarf1.c component or the parse die and parse line table functions to minimize the risk of exploitation. Avoid using specially crafted ELF files that could trigger the buffer over-read vulnerability.

Fix

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-07759
CVE-2017-15020
MGASA-2019-0169
USN-4336-2

Affected Products

Gnu Binutils
Ubuntu