First published: Sat Sep 30 2017(Updated: )
_bfd_elf_slurp_version_tables in elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted ELF file.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNU Binutils | =2.29 | |
debian/binutils | 2.35.2-2 2.40-2 2.43.1-5 |
https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=bd61e135492ecf624880e6b78e5fcde3c9716df6
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2017-14938.
The title of this vulnerability is `_bfd_elf_slurp_version_tables` in `elf.c` in the Binary File Descriptor (BFD) library (aka libbfd) as distributed in GNU Binutils 2.29.
This vulnerability allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted ELF file.
The affected software is GNU Binutils version 2.29.
To fix this vulnerability, update to version 2.29.90.20180122-1 or later of GNU Binutils.