CVE-2017-14934: Medium severity GNU binutils vulnerability
Published Sep 29, 2017
·Updated
processdebuginfo in dwarf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (infinite loop) via a crafted ELF file that contains a negative size value in a CU structure.
Affected Software
1 affected component
GNU binutils=2.29
Remediation
Patch Available
Event History
Sep 29, 2017
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-14934?
CVE-2017-14934 is classified as a denial of service vulnerability.
2
How do I fix CVE-2017-14934?
To fix CVE-2017-14934, upgrade to a version of GNU Binutils later than 2.29 that addresses this vulnerability.
3
Who is affected by CVE-2017-14934?
Users of GNU Binutils version 2.29 are at risk of being affected by CVE-2017-14934.
4
What kind of attack does CVE-2017-14934 allow?
CVE-2017-14934 allows remote attackers to cause a denial of service via a crafted ELF file.
5
What is the cause of CVE-2017-14934?
CVE-2017-14934 is caused by a negative size value in a CU structure within the Binary File Descriptor library.