CVE-2017-14128: Medium severity binutils vulnerability
Last updated 24 July 2024
Other sources
The decodelineinfo function in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (read1byte heap-based buffer over-read and application crash) via a crafted ELF file.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2017-14128.
What is the severity of CVE-2017-14128?
The severity of CVE-2017-14128 is a denial of service (DoS) vulnerability.
Which software is affected by CVE-2017-14128?
The software affected by CVE-2017-14128 is the Binary File Descriptor (BFD) library (libbfd) in GNU Binutils 2.29.
How can an attacker exploit CVE-2017-14128?
An attacker can exploit CVE-2017-14128 by using a crafted ELF file to cause a denial of service (DoS) and crash the application.
Is there a recommended remedy for CVE-2017-14128?
Yes, for Ubuntu, the recommended remedy for CVE-2017-14128 is to upgrade to a version equal to or higher than 2.26.1-1ubuntu1~16.04.8+. For Debian, versions 2.31.1-16, 2.35.2-2, 2.40-2, and 2.41-5 are recommended remedies.