Out-of-bounds read in Binutils - CVE-2017-6969
Published: March 17, 2017 / Updated: August 8, 2020
Vulnerability identifier: #VU39450
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-6969
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to #BASIC_IMPACT#.
readelf in GNU Binutils 2.28 is vulnerable to a heap-based buffer over-read while processing corrupt RL78 binaries. The vulnerability can trigger program crashes. It may lead to an information leak as well.
Affected software
Binutils
Gentoo Linux
Gentoo Linux
How to mitigate CVE-2017-6969
Install update from vendor's website.