ID:3792 - Exploit for Input validation error in Binutils - CVE-2017-9748

 
Main Vulnerability Database Exploits ID:3792 - Exploit for Input validation error in Binutils - CVE-2017-9748

ID:3792 - Exploit for Input validation error in Binutils - CVE-2017-9748

Published: August 9, 2020


Vulnerability identifier: #VU38840
Vulnerability risk: Medium
CVE-ID: CVE-2017-9748
CWE-ID: CWE-20
Exploitation vector: Local access
Vulnerable software:
Binutils

Link to public exploit:


Vulnerability description

The vulnerability allows remote attackers to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by mishandling of this file during "objdump -D" execution.


Remediation

Install update from vendor's website.