CVE-2017-7302

The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has a swap_std_reloc_out function in bfd/aoutx.h that is vulnerable to an invalid read (of size 4) because of missing checks for relocs that could not be recognised. This vulnerability causes Binutils utilities like strip to crash.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gnu:binutils:2.28:*:*:*:*:*:*:*

History

21 Nov 2024, 03:31

Type Values Removed Values Added
References () http://www.securityfocus.com/bid/97216 - Patch, VDB Entry () http://www.securityfocus.com/bid/97216 - Patch, VDB Entry
References () https://sourceware.org/bugzilla/show_bug.cgi?id=20921 - Issue Tracking, Patch () https://sourceware.org/bugzilla/show_bug.cgi?id=20921 - Issue Tracking, Patch

Information

Published : 2017-03-29 15:59

Updated : 2024-11-21 03:31


NVD link : CVE-2017-7302

Mitre link : CVE-2017-7302

CVE.ORG link : CVE-2017-7302


JSON object : View

Products Affected

gnu

  • binutils
CWE
CWE-125

Out-of-bounds Read