CVE-2017-14974: Null Pointer Dereference
The getsyntheticsymtab functions in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, mishandle the failure of a certain canonicalization step, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted ELF file, related to elf32-i386.c and elf64-x86-64.c.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-14974?
CVE-2017-14974 has been classified as a medium severity vulnerability.
How do I fix CVE-2017-14974?
To fix CVE-2017-14974, upgrade GNU Binutils to version 2.30 or later.
What type of vulnerability is CVE-2017-14974?
CVE-2017-14974 is a denial of service vulnerability caused by a NULL pointer dereference.
Who is affected by CVE-2017-14974?
CVE-2017-14974 affects users of GNU Binutils version 2.29.
What can an attacker do with CVE-2017-14974?
An attacker can exploit CVE-2017-14974 to cause an application crash by triggering a denial of service.