CVE-2017-14940: Null Pointer Dereference
Last updated 24 July 2024
Other sources
scanunitforsymbols in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted ELF file.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2017-14940?
CVE-2017-14940 is a vulnerability in the Binary File Descriptor (BFD) library in GNU Binutils 2.29 that allows remote attackers to cause a denial of service via a crafted ELF file.
How can the CVE-2017-14940 vulnerability be exploited?
The CVE-2017-14940 vulnerability can be exploited by sending a crafted ELF file to the target, causing a NULL pointer dereference and application crash.
Which software is affected by CVE-2017-14940?
The affected software is Binutils version 2.26.1-1ubuntu1~16.04.8+ through 2.29.90.20180122-1.
How can I mitigate the CVE-2017-14940 vulnerability?
To mitigate the CVE-2017-14940 vulnerability, update Binutils to version 2.31.1-16 or later.
Are there any references for CVE-2017-14940?
Yes, you can find more information about CVE-2017-14940 at the following links: [https://blogs.gentoo.org/ago/2017/09/26/binutils-null-pointer-dereference-in-scan_unit_for_symbols-dwarf2-c/](https://blogs.gentoo.org/ago/2017/09/26/binutils-null-pointer-dereference-in-scan_unit_for_symbols-dwarf2-c/), [https://sourceware.org/bugzilla/show_bug.cgi?id=22166](https://sourceware.org/bugzilla/show_bug.cgi?id=22166), [https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=0d76029f92182c3682d8be2c833d45bc9a2068fe](https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=0d76029f92182c3682d8be2c833d45bc9a2068fe)