CVE-2017-7303Out-of-bounds Read in Binutils

CWE-125Out-of-bounds Read7 documents7 sources
Severity
7.5HIGHNVD
EPSS
0.4%
top 38.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 29
Latest updateMay 17

Description

The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid read (of size 4) because of missing a check (in the find_link function) for null headers before attempting to match them. This vulnerability causes Binutils utilities like strip to crash.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

Debiangnu/binutils< 2.27.51.20161212-1+3
NVDgnu/binutils2.28

Patches

🔴Vulnerability Details

3
GHSA
GHSA-2qxc-885r-78rq: The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 22022-05-17
CVEList
CVE-2017-7303: The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 22017-03-29
OSV
CVE-2017-7303: The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 22017-03-29

📋Vendor Advisories

2
Debian
CVE-2017-7303: binutils - The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Bin...2017
Red Hat
binutils: Out-of-bounds read in find_link function2016-12-03

💬Community

1
Bugzilla
CVE-2017-7303 binutils: Out-of-bounds read in find_link function2017-04-10
CVE-2017-7303 — Out-of-bounds Read in GNU Binutils | cvebase