CVE-2017-14933: Medium severity GNU binutils vulnerability
Published Sep 29, 2017
·Updated
readformattedentries in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (infinite loop) via a crafted ELF file.
Affected Software
1 affected component
GNU binutils=2.29
Remediation
Patch Available
Event History
Sep 29, 2017
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-14933?
CVE-2017-14933 is classified as a denial of service vulnerability.
2
How do I fix CVE-2017-14933?
To fix CVE-2017-14933, update to a version of GNU Binutils that is patched for this vulnerability.
3
Which versions of GNU Binutils are affected by CVE-2017-14933?
CVE-2017-14933 affects GNU Binutils version 2.29.
4
What type of attack does CVE-2017-14933 enable?
CVE-2017-14933 enables remote attackers to cause a denial of service through an infinite loop.
5
What file format is exploited in CVE-2017-14933?
CVE-2017-14933 is exploited via a crafted ELF file.