CVE-2017-16826: Buffer Overflow
Last updated 24 July 2024
Other sources
The coffslurplinetable function in coffcode.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, allows remote attackers to cause a denial of service (invalid memory access and application crash) or possibly have unspecified other impact via a crafted PE file.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2017-16826.
What software is affected by this vulnerability?
The affected software is GNU Binutils version 2.29.1.
How can this vulnerability be exploited?
This vulnerability can be exploited by remote attackers to cause a denial of service or potentially have unspecified other impact via a crafted input.
Is there a fix available for this vulnerability?
Yes, there are fixes available. For Ubuntu, use version 2.26.1-1ubuntu1~16.04.8+ or 2.29.90.20180122-1. For Debian, use versions 2.31.1-16, 2.35.2-2, 2.40-2, or 2.41-5.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability at the following references: [link1](https://sourceware.org/bugzilla/show_bug.cgi?id=22376), [link2](https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=a67d66eb97e7613a38ffe6622d837303b3ecd31d), [link3](https://security.gentoo.org/glsa/201811-17).