CVE-2017-7299

MEDIUM

GNU Binutils 2.28 - Memory Corruption

Title source: llm
STIX 2.1

Description

The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has an invalid read (of size 8) because the code to emit relocs (bfd_elf_final_link function in bfd/elflink.c) does not check the format of the input file before trying to read the ELF reloc section header. The vulnerability leads to a GNU linker (ld) program crash.

References (2)

Core 2
Core References
Issue Tracking, Patch x_refsource_confirm
https://sourceware.org/bugzilla/show_bug.cgi?id=20908
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/97217

Scores

CVSS v3 5.5
EPSS 0.0026
EPSS Percentile 49.5%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Details

CWE
CWE-125
Status published
Products (1)
gnu/binutils 2.28
Published Mar 29, 2017
Tracked Since Feb 18, 2026