CVE-2017-8396

The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid read of size 1 because the existing reloc offset range tests didn't catch small negative offsets less than the size of the reloc field. This vulnerability causes programs that conduct an analysis of binary programs using the libbfd library, such as objdump, to crash.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gnu:binutils:2.28:*:*:*:*:*:*:*

History

21 Nov 2024, 03:33

Type Values Removed Values Added
References () https://security.gentoo.org/glsa/201709-02 - () https://security.gentoo.org/glsa/201709-02 -
References () https://sourceware.org/bugzilla/show_bug.cgi?id=21432 - Issue Tracking, Patch, Third Party Advisory () https://sourceware.org/bugzilla/show_bug.cgi?id=21432 - Issue Tracking, Patch, Third Party Advisory

Information

Published : 2017-05-01 18:59

Updated : 2024-11-21 03:33


NVD link : CVE-2017-8396

Mitre link : CVE-2017-8396

CVE.ORG link : CVE-2017-8396


JSON object : View

Products Affected

gnu

  • binutils
CWE
CWE-20

Improper Input Validation