PT-2017-4316 · Gnu+2 · Gnu Binutils+2

Published

2017-11-02

·

Updated

2024-06-15

·

CVE-2017-16831

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: GNU Binutils version 2.29.1
Description: The issue is related to the coffgen.c component in the Binary File Descriptor (BFD) library, which does not validate the symbol count. This allows remote attackers to cause a denial of service, potentially leading to an integer overflow and application crash, or excessive memory allocation, via a crafted PE file. The vulnerability may also allow attackers to access confidential data, compromise its integrity, and disrupt service.
Recommendations: For GNU Binutils version 2.29.1, consider updating to a newer version that addresses the issue, as the current version does not validate the symbol count in the coffgen.c component, leading to potential security risks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-07771
CVE-2017-16831
OPENSUSE-SU-2018_3223-1
OPENSUSE-SU-2018_3323-1
OPENSUSE-SU-2024:10651-1
SUSE-SU-2018:3170-1
SUSE-SU-2018:3207-1
SUSE-SU-2018:3207-2
USN-4336-2

Affected Products

Gnu Binutils
Suse
Ubuntu