CVE-2017-9043Improper Input Validation in Binutils

Severity
7.8HIGHNVD
EPSS
0.5%
top 35.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 18
Latest updateMay 17

Description

readelf.c in GNU Binutils 2017-04-12 has a "shift exponent too large for type unsigned long" issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted ELF file.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

Debiangnu/binutils< 2.29-1+3
NVDgnu/binutils2.28

Patches

🔴Vulnerability Details

3
GHSA
GHSA-x7qx-55qv-w9fc: readelf2022-05-17
CVEList
CVE-2017-9043: readelf2017-05-18
OSV
CVE-2017-9043: readelf2017-05-18

📋Vendor Advisories

2
Red Hat
binutils: Shift exponent too large for type unsigned long in readelf.c2017-05-12
Debian
CVE-2017-9043: binutils - readelf.c in GNU Binutils 2017-04-12 has a "shift exponent too large for type un...2017

💬Community

1
Bugzilla
CVE-2017-9043 binutils: Shift exponent too large for type unsigned long in readelf.c2017-05-18
CVE-2017-9043 — Improper Input Validation in Binutils | cvebase