CVE-2017-8392
published 2017-05-01CVE-2017-8392: The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid read of size 8 because of missing a…
PriorityP433high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
1.45%
70.6th percentile
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid read of size 8 because of missing a check to determine whether symbols are NULL in the _bfd_dwarf2_find_nearest_line function. This vulnerability causes programs that conduct an analysis of binary programs using the libbfd library, such as objdump, to crash.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | binutils | — | — |
| gnu | binutils | — | — |
| gnu | binutils | >= 0 < 2.30-21ubuntu1~18.04.1 | 2.30-21ubuntu1~18.04.1 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5LOW
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r84j-qc9r-qrgh: The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2
ghsa_unreviewed·2022-05-17
CVE-2017-8392 [HIGH] CWE-476 GHSA-r84j-qc9r-qrgh: The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid read of size 8 because of missing a check to determine whether symbols are NULL in the _bfd_dwarf2_find_nearest_line function. This vulnerability causes programs that conduct an analysis of binary programs using the libbfd library, such as objdump, to crash.
OSV
CVE-2017-8392: The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2
osv·2017-05-01·CVSS 7.5
CVE-2017-8392 [HIGH] CVE-2017-8392: The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid read of size 8 because of missing a check to determine whether symbols are NULL in the _bfd_dwarf2_find_nearest_line function. This vulnerability causes programs that conduct an analysis of binary programs using the libbfd library, such as objdump, to crash.
Red Hat
binutils: NULL pointer dereference in the _bfd_dwarf2_find_nearest_line function
vendor_redhat·2017-04-22·CVSS 7.5
CVE-2017-8392 [HIGH] CWE-476 binutils: NULL pointer dereference in the _bfd_dwarf2_find_nearest_line function
binutils: NULL pointer dereference in the _bfd_dwarf2_find_nearest_line function
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid read of size 8 because of missing a check to determine whether symbols are NULL in the _bfd_dwarf2_find_nearest_line function. This vulnerability causes programs that conduct an analysis of binary programs using the libbfd library, such as objdump, to crash.
Package: binutils (Red Hat Enterprise Linux 5) - Will not fix
Package: binutils220 (Red Hat Enterprise Linux 5) - Will not fix
Package: binutils (Red Hat Enterprise Linux 6) - Will not fix
Package: binutils (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2017-8392: binutils - The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Bin...
vendor_debian·2017·CVSS 7.5
CVE-2017-8392 [HIGH] CVE-2017-8392: binutils - The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Bin...
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid read of size 8 because of missing a check to determine whether symbols are NULL in the _bfd_dwarf2_find_nearest_line function. This vulnerability causes programs that conduct an analysis of binary programs using the libbfd library, such as objdump, to crash.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
2017-05-01
Published