CVE-2017-14930: High severity GNU binutils vulnerability
Last updated 24 July 2024
Other sources
Memory leak in decodelineinfo in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (memory consumption) via a crafted ELF file.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2017-14930?
CVE-2017-14930 is a vulnerability in the Binary File Descriptor (BFD) library, also known as libbfd, which allows remote attackers to cause a denial of service by consuming excessive memory.
How does the CVE-2017-14930 vulnerability manifest?
The vulnerability manifests as a memory leak in the decode_line_info function in dwarf2.c within the libbfd library.
What software is affected by CVE-2017-14930?
The CVE-2017-14930 vulnerability affects GNU Binutils version 2.29 and possibly other versions.
How can I mitigate the CVE-2017-14930 vulnerability?
To mitigate the vulnerability, you can update the binutils package to version 2.26.1-1ubuntu1~16.04.8+ or higher, or version 2.30 or higher.
Where can I find more information about CVE-2017-14930?
You can find more information about CVE-2017-14930 on the Sourceware Bugzilla, Launchpad, and MITRE CVE websites. (Please note that hyperlinks are not allowed in this format, so you will need to search for the specific websites using the provided descriptions.)