CVE-2017-17080 Information

Description

elf.c in the Binary File Descriptor (BFD) library (aka libbfd) as distributed in GNU Binutils 2.29.1 does not validate sizes of core notes which allows remote attackers to cause a denial of service (bfd_getl32 heap-based buffer over-read and application crash) via a crafted object file related to elfcore_grok_netbsd_procinfo elfcore_grok_openbsd_procinfo and elfcore_grok_nto_status.

CVSS Vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Reference

https://security.gentoo.org/glsa/201811-17 https://sourceware.org/bugzilla/show_bug.cgi?id=22421

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

REQUIRED

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

NONE

Base Score

HIGH

Base Severity

5.5

Share on: