CVE-2017-14129: Medium severity binutils vulnerability
Published Sep 4, 2017
·Updated
Last updated 24 July 2024
Other sources
The readsection function in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (parsecompunit heap-based buffer over-read and application crash) via a crafted ELF file.
Affected Software
2 affected componentsFixes available
GNU binutils=2.29
debian/binutils
2.35.2-22.40-22.44-3
Remediation
Patch Available
Event History
Sep 4, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·10:29 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·01:18 AM
RemedyDescriptionSeverityAffected Software
Feb 27, 2025
Data Sourced
via Debian·03:36 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2017-14129.
2
What is the affected software?
The affected software is Binutils.
3
What is the severity of CVE-2017-14129?
The severity of CVE-2017-14129 is moderate.
4
How can remote attackers exploit CVE-2017-14129?
Remote attackers can exploit CVE-2017-14129 by sending a crafted ELF file, causing a denial of service and application crash.
5
How can I fix CVE-2017-14129?
To fix CVE-2017-14129, update to at least version 2.29.1 of Binutils.