CVE-2017-8396Improper Input Validation in Binutils

Severity
7.5HIGHNVD
EPSS
0.4%
top 40.51%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 1
Latest updateMay 17

Description

The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid read of size 1 because the existing reloc offset range tests didn't catch small negative offsets less than the size of the reloc field. This vulnerability causes programs that conduct an analysis of binary programs using the libbfd library, such as objdump, to crash.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

Debiangnu/binutils< 2.28-5+3
NVDgnu/binutils2.28

Patches

🔴Vulnerability Details

3
GHSA
GHSA-wv8w-rw6r-ppxm: The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 22022-05-17
OSV
CVE-2017-8396: The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 22017-05-01
CVEList
CVE-2017-8396: The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 22017-05-01

📋Vendor Advisories

3
Ubuntu
GNU binutils vulnerabilities2021-07-21
Red Hat
binutils: Out-of-bounds read in the existing reloc offset range tests2017-04-22
Debian
CVE-2017-8396: binutils - The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Bin...2017

💬Community

1
Bugzilla
CVE-2017-8396 binutils: Out-of-bounds read in the existing reloc offset range tests2017-05-10
CVE-2017-8396 — Improper Input Validation in Binutils | cvebase