Out-of-bounds read in Binutils - CVE-2017-16829

 

Out-of-bounds read in Binutils - CVE-2017-16829

Published: November 15, 2017 / Updated: February 10, 2022


Vulnerability identifier: #VU37961
CSH Severity: Medium
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-16829
CWE-ID: CWE-125
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to perform denial of service (DoS) attack.

The vulnerability exists due to a boundary condition within the elf-properties.c function in the Binary File Descriptor (BFD) library (aka libbfd), as distributed file. A remote attacker can create a specially crafted file, trick the victim into opening it, trigger out-of-bounds read error and crash the affected application.


Affected software

Binutils
Gentoo Linux
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Software Development Kit 12
gdb-debugsource
gdbserver
gdbserver-debuginfo
gdb-debuginfo-32bit
gdbserver-debuginfo-32bit
gdbserver-32bit
gdb
gdb-debuginfo
EMC Cloud Tiering Appliance

How to mitigate CVE-2017-16829

Install update from vendor's website.

gdb-debugsource - addressed in versions 12.1-2.20.1, 13.2-2.23.1
gdbserver - addressed in versions 12.1-2.20.1, 13.2-2.23.1
gdbserver-debuginfo - addressed in versions 12.1-2.20.1, 13.2-2.23.1
gdb-debuginfo-32bit - addressed in versions 12.1-2.20.1, 13.2-2.23.1
gdbserver-debuginfo-32bit - addressed in versions 12.1-2.20.1, 13.2-2.23.1
gdbserver-32bit - addressed in versions 12.1-2.20.1, 13.2-2.23.1
gdb - addressed in versions 12.1-2.20.1, 13.2-2.23.1
gdb-debuginfo - addressed in versions 12.1-2.20.1, 13.2-2.23.1
EMC Cloud Tiering Appliance - update to 13.2.0.2.29

External References

Related Security Bulletins