CVE-2017-7226 Information
Feb 14, 2021
cve
Description
The pe_ILF_object_p function in the Binary File Descriptor (BFD) library (aka libbfd) as distributed in GNU Binutils 2.28 is vulnerable to a heap-based buffer over-read of size 4049 because it uses the strlen function instead of strnlen leading to program crashes in several utilities such as addr2line size and strings. It could lead to information disclosure as well.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Reference
https://sourceware.org/bugzilla/show_bug.cgi?id=20905
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
HIGH
Base Severity
9.1
Share on: