CVE-2017-14938: Medium severity GNU binutils vulnerability
bfdelfslurpversiontables in elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted ELF file.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2017-14938.
What is the title of this vulnerability?
The title of this vulnerability is `_bfd_elf_slurp_version_tables` in `elf.c` in the Binary File Descriptor (BFD) library (aka libbfd) as distributed in GNU Binutils 2.29.
What is the impact of this vulnerability?
This vulnerability allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted ELF file.
Which software is affected by this vulnerability?
The affected software is GNU Binutils version 2.29.
How can I fix this vulnerability?
To fix this vulnerability, update to version 2.29.90.20180122-1 or later of GNU Binutils.