CVE-2017-15023
published 2017-10-05CVE-2017-15023: read_formatted_entries in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, does not properly validate…
PriorityP421medium5.5CVSS 3.0
AVLACLPRNUIRSUCNINAH
EPSS
2.07%
79.5th percentile
read_formatted_entries in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, does not properly validate the format count, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted ELF file, related to concat_filename.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | binutils | < binutils 2.29.90.20180122-1 (bookworm) | binutils 2.29.90.20180122-1 (bookworm) |
| debian | binutils | — | — |
| gnu | binutils | — | — |
| gnu | binutils | >= 0 < 2.29.90.20180122-1 | 2.29.90.20180122-1 |
| gnu | binutils | >= 0 < 2.29.90.20180122-1 | 2.29.90.20180122-1 |
| gnu | binutils | >= 0 < 2.29.90.20180122-1 | 2.29.90.20180122-1 |
| gnu | binutils | >= 0 < 2.29.90.20180122-1 | 2.29.90.20180122-1 |
| gnu | binutils | >= 0 < 2.26.1-1ubuntu1~16.04.8+esm1 | 2.26.1-1ubuntu1~16.04.8+esm1 |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v237-vcgw-685x: read_formatted_entries in dwarf2
ghsa_unreviewed·2022-05-14
CVE-2017-15023 [MEDIUM] CWE-476 GHSA-v237-vcgw-685x: read_formatted_entries in dwarf2
read_formatted_entries in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, does not properly validate the format count, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted ELF file, related to concat_filename.
GHSA
GHSA-pmp5-rw9v-rgv5: dwarf2
ghsa_unreviewed·2022-05-14·CVSS 5.5
CVE-2017-15939 [MEDIUM] CWE-476 GHSA-pmp5-rw9v-rgv5: dwarf2
dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, mishandles NULL files in a .debug_line file table, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted ELF file, related to concat_filename. NOTE: this issue is caused by an incomplete fix for CVE-2017-15023.
OSV
CVE-2017-15939: dwarf2
osv·2017-10-27·CVSS 5.5
CVE-2017-15939 [MEDIUM] CVE-2017-15939: dwarf2
dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, mishandles NULL files in a .debug_line file table, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted ELF file, related to concat_filename. NOTE: this issue is caused by an incomplete fix for CVE-2017-15023.
OSV
CVE-2017-15023: read_formatted_entries in dwarf2
osv·2017-10-05·CVSS 5.5
CVE-2017-15023 [MEDIUM] CVE-2017-15023: read_formatted_entries in dwarf2
read_formatted_entries in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, does not properly validate the format count, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted ELF file, related to concat_filename.
Red Hat
binutils: NULL pointer dereference in read_formatted_entries
vendor_redhat·2017-09-25·CVSS 5.5
CVE-2017-15023 [MEDIUM] CWE-476 binutils: NULL pointer dereference in read_formatted_entries
binutils: NULL pointer dereference in read_formatted_entries
read_formatted_entries in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, does not properly validate the format count, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted ELF file, related to concat_filename.
Package: binutils (Red Hat Enterprise Linux 5) - Will not fix
Package: binutils220 (Red Hat Enterprise Linux 5) - Will not fix
Package: binutils (Red Hat Enterprise Linux 6) - Will not fix
Package: binutils (Red Hat Enterprise Linux 7) - Will not fix
Red Hat
binutils: NULL pointer dereference in the concat_filename
vendor_redhat·2017-09-25·CVSS 5.5
CVE-2017-15939 [MEDIUM] CWE-476 binutils: NULL pointer dereference in the concat_filename
binutils: NULL pointer dereference in the concat_filename
dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, mishandles NULL files in a .debug_line file table, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted ELF file, related to concat_filename. NOTE: this issue is caused by an incomplete fix for CVE-2017-15023.
Package: binutils (Red Hat Enterprise Linux 5) - Will not fix
Package: binutils220 (Red Hat Enterprise Linux 5) - Will not fix
Package: binutils (Red Hat Enterprise Linux 6) - Will not fix
Package: binutils (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2017-15939: binutils - dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distribute...
vendor_debian·2017·CVSS 5.5
CVE-2017-15939 [MEDIUM] CVE-2017-15939: binutils - dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distribute...
dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, mishandles NULL files in a .debug_line file table, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted ELF file, related to concat_filename. NOTE: this issue is caused by an incomplete fix for CVE-2017-15023.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
Debian
CVE-2017-15023: binutils - read_formatted_entries in dwarf2.c in the Binary File Descriptor (BFD) library (...
vendor_debian·2017·CVSS 5.5
CVE-2017-15023 [MEDIUM] CVE-2017-15023: binutils - read_formatted_entries in dwarf2.c in the Binary File Descriptor (BFD) library (...
read_formatted_entries in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, does not properly validate the format count, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted ELF file, related to concat_filename.
Scope: local
bookworm: resolved (fixed in 2.29.90.20180122-1)
bullseye: resolved (fixed in 2.29.90.20180122-1)
forky: resolved (fixed in 2.29.90.20180122-1)
sid: resolved (fixed in 2.29.90.20180122-1)
trixie: resolved (fixed in 2.29.90.20180122-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-15939 binutils: NULL pointer dereference in the concat_filename
bugzilla·2017-11-07·CVSS 5.5
CVE-2017-15939 [MEDIUM] CVE-2017-15939 binutils: NULL pointer dereference in the concat_filename
CVE-2017-15939 binutils: NULL pointer dereference in the concat_filename
dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, mishandles NULL files in a .debug_line file table, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted ELF file, related to concat_filename. NOTE: this issue is caused by an incomplete fix for CVE-2017-15023.
Upstream issue:
https://sourceware.org/bugzilla/show_bug.cgi?id=22205
Upstream patches:
https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=a54018b72d75abf2e74bf36016702da06399c1d9
Discussion:
Created binutils tracking bugs for this issue:
Affects: fedora-all [bug 1499311]
Created mingw-binutils tracking bugs for this issue:
Bugzilla
CVE-2017-15023 binutils: NULL pointer dereference in read_formatted_entries
bugzilla·2017-10-10·CVSS 5.5
CVE-2017-15023 [MEDIUM] CVE-2017-15023 binutils: NULL pointer dereference in read_formatted_entries
CVE-2017-15023 binutils: NULL pointer dereference in read_formatted_entries
read_formatted_entries in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, does not properly validate the format count, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted ELF file, related to concat_filename.
Upstream issue:
https://sourceware.org/bugzilla/show_bug.cgi?id=22200
Upstream patch:
https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=c361faae8d964db951b7100cada4dcdc983df1bf
Discussion:
Created binutils tracking bugs for this issue:
Affects: fedora-all [bug 1499311]
Created mingw-binutils tracking bugs for this issue:
Affects: epel-all [bug 1499310]
Bugzilla
CVE-2017-14529 CVE-2017-14729 CVE-2017-14745 CVE-2017-14930 CVE-2017-14932 CVE-2017-14933 CVE-2017-14934 CVE-2017-14938 CVE-2017-14939 CVE-2017-14940 CVE-2017-14974 CVE-2017-15020 CVE-2017-15021 CVE-2
bugzilla·2017-10-06·CVSS 5.5
CVE-2017-14529 [MEDIUM] CVE-2017-14529 CVE-2017-14729 CVE-2017-14745 CVE-2017-14930 CVE-2017-14932 CVE-2017-14933 CVE-2017-14934 CVE-2017-14938 CVE-2017-14939 CVE-2017-14940 CVE-2017-14974 CVE-2017-15020 CVE-2017-15021 CVE-2
CVE-2017-14529 CVE-2017-14729 CVE-2017-14745 CVE-2017-14930 CVE-2017-14932 CVE-2017-14933 CVE-2017-14934 CVE-2017-14938 CVE-2017-14939 CVE-2017-14940 CVE-2017-14974 CVE-2017-15020 CVE-2017-15021 CVE-2017-15022 ... binutils: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the releva
Bugzilla
CVE-2017-14529 CVE-2017-14729 CVE-2017-14745 CVE-2017-14930 CVE-2017-14932 CVE-2017-14933 CVE-2017-14934 CVE-2017-14938 CVE-2017-14939 CVE-2017-14940 CVE-2017-14974 CVE-2017-15020 CVE-2017-15021 CVE-2
bugzilla·2017-10-06·CVSS 5.5
CVE-2017-14529 [MEDIUM] CVE-2017-14529 CVE-2017-14729 CVE-2017-14745 CVE-2017-14930 CVE-2017-14932 CVE-2017-14933 CVE-2017-14934 CVE-2017-14938 CVE-2017-14939 CVE-2017-14940 CVE-2017-14974 CVE-2017-15020 CVE-2017-15021 CVE-2
CVE-2017-14529 CVE-2017-14729 CVE-2017-14745 CVE-2017-14930 CVE-2017-14932 CVE-2017-14933 CVE-2017-14934 CVE-2017-14938 CVE-2017-14939 CVE-2017-14940 CVE-2017-14974 CVE-2017-15020 CVE-2017-15021 CVE-2017-15022 ... mingw-binutils: various flaws [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the rele
arXiv
HyperGo: Probability-based Directed Hybrid Fuzzing
arxiv_fulltext·2025-02-12
HyperGo: Probability-based Directed Hybrid Fuzzing
HyperGo: Probability-based Directed Hybrid Fuzzing
Peihong Lin
National University of Defense Technology
Kaifu Qu
Changsha
China
[email protected]
Pengfei Wang
National University of Defense Technology
Kaifu Qu
Changsha
China
[email protected]
Xu Zhou
National University of Defense Technology
Kaifu Qu
Changsha
China
[email protected]
Wei Xie
National University of Defense Technology
Kaifu Qu
Changsha
China
[email protected]
Kai Lu
National University of Defense Technology
Kaifu Qu
Changsha
China
[email protected]
Gen Zhang
National University of Defense Technology
Kaifu Qu
Changsha
China
[email protected]
## Abstract
Directed grey-box fuzzing (DGF) is a target-guided fuzzing intended for testing specific targets (e.g., the potential buggy code). Despite numerous techn
http://www.securityfocus.com/bid/101611https://blogs.gentoo.org/ago/2017/10/03/binutils-null-pointer-dereference-in-concat_filename-dwarf2-c/https://security.gentoo.org/glsa/201801-01https://sourceware.org/bugzilla/show_bug.cgi?id=22200https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git%3Bh=c361faae8d964db951b7100cada4dcdc983df1bfhttp://www.securityfocus.com/bid/101611https://blogs.gentoo.org/ago/2017/10/03/binutils-null-pointer-dereference-in-concat_filename-dwarf2-c/https://security.gentoo.org/glsa/201801-01https://sourceware.org/bugzilla/show_bug.cgi?id=22200https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git%3Bh=c361faae8d964db951b7100cada4dcdc983df1bf
2017-10-05
Published