CVE-2017-15024: Medium severity GNU binutils vulnerability
findabstractinstancename in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (infinite recursion and application crash) via a crafted ELF file.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2017-15024.
What is the title of this vulnerability?
The title of this vulnerability is 'find_abstract_instance_name in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd) as ...'
What is the affected software?
The affected software is the Binary File Descriptor (BFD) library (aka libbfd) as distributed in GNU Binutils 2.29.
What is the impact of this vulnerability?
This vulnerability allows remote attackers to cause a denial of service (infinite recursion and application crash) via a crafted ELF file.
How can I fix this vulnerability?
To fix this vulnerability, you should apply the recommended security updates for the affected software.