CVE-2017-7210Improper Restriction of Operations within the Bounds of a Memory Buffer in Binutils

Severity
5.5MEDIUMNVD
EPSS
0.3%
top 45.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 21
Latest updateMay 14

Description

objdump in GNU Binutils 2.28 is vulnerable to multiple heap-based buffer over-reads (of size 1 and size 8) while handling corrupt STABS enum type strings in a crafted object file, leading to program crash.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

Debiangnu/binutils< 2.28-3+3
NVDgnu/binutils2.28

Patches

🔴Vulnerability Details

3
GHSA
GHSA-fcgq-x9jj-22rf: objdump in GNU Binutils 22022-05-14
CVEList
CVE-2017-7210: objdump in GNU Binutils 22017-03-21
OSV
CVE-2017-7210: objdump in GNU Binutils 22017-03-21

📋Vendor Advisories

3
Ubuntu
GNU binutils vulnerabilities2021-07-21
Red Hat
binutils: Heap-based buffer over-reads in objdump2017-02-14
Debian
CVE-2017-7210: binutils - objdump in GNU Binutils 2.28 is vulnerable to multiple heap-based buffer over-re...2017

💬Community

1
Bugzilla
CVE-2017-7210 binutils: Heap-based buffer over-reads in objdump2017-03-24
CVE-2017-7210 — GNU Binutils vulnerability | cvebase