CVE-2017-14529: Medium severity binutils vulnerability
Published Sep 18, 2017
·Updated
Last updated 24 July 2024
Other sources
The peprintidata function in peXXigen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, mishandles HintName vector entries, which allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted PE file, related to the bfdgetl16 function.
Affected Software
2 affected componentsFixes available
GNU binutils=2.29
debian/binutils
2.35.2-22.40-22.44-3
Remediation
Patch Available
Event History
Sep 18, 2017
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Jan 11, 2024
Data Sourced
via Launchpad·10:30 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·01:18 AM
RemedyDescriptionSeverityAffected Software
Feb 27, 2025
Data Sourced
via Debian·03:36 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is CVE-2017-14529?
CVE-2017-14529 is a vulnerability in the Binary File Descriptor (BFD) library (libbfd) in GNU Binutils 2.29 that allows remote attackers to cause a denial of service.
2
How does CVE-2017-14529 impact the affected software?
CVE-2017-14529 can cause a denial of service (heap-based buffer over-read and application crash) in the affected software.