Buffer overflow in Binutils - CVE-2017-17126

 

Buffer overflow in Binutils - CVE-2017-17126

Published: December 4, 2017 / Updated: August 8, 2020


Vulnerability identifier: #VU37863
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-17126
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

The load_debug_section function in readelf.c in GNU Binutils 2.29.1 allows remote attackers to cause a denial of service (invalid memory access and application crash) or possibly have unspecified other impact via an ELF file that lacks section headers.


Affected software

Binutils
Gentoo Linux

How to mitigate CVE-2017-17126

Install update from vendor's website.


External References

Related Security Bulletins