CVE-2017-8396 — Improper Input Validation in Binutils
Severity
7.5HIGHNVD
EPSS
0.4%
top 40.51%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 1
Latest updateMay 17
Description
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid read of size 1 because the existing reloc offset range tests didn't catch small negative offsets less than the size of the reloc field. This vulnerability causes programs that conduct an analysis of binary programs using the libbfd library, such as objdump, to crash.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6
Affected Packages2 packages
Patches
🔴Vulnerability Details
3GHSA▶
GHSA-wv8w-rw6r-ppxm: The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2↗2022-05-17
OSV▶
CVE-2017-8396: The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2↗2017-05-01
CVEList▶
CVE-2017-8396: The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2↗2017-05-01
📋Vendor Advisories
3💬Community
1Bugzilla
▶