CVE-2017-13757

MEDIUM

GNU Binutils - Out-of-Bounds Read

Title source: rule
STIX 2.1

Description

The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, does not validate the PLT section size, which allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file, related to elf_i386_get_synthetic_symtab in elf32-i386.c and elf_x86_64_get_synthetic_symtab in elf64-x86-64.c.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/100532
Issue Tracking, Patch, Third Party Advisory x_refsource_confirm
https://sourceware.org/bugzilla/show_bug.cgi?id=22018

Scores

CVSS v3 5.5
EPSS 0.0045
EPSS Percentile 63.9%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Details

CWE
CWE-125
Status published
Products (1)
gnu/binutils 2.29
Published Aug 29, 2017
Tracked Since Feb 18, 2026