CVE-2017-16830: Integer Overflow
Published Nov 15, 2017
·Updated
The printgnupropertynote function in readelf.c in GNU Binutils 2.29.1 does not have integer-overflow protection on 32-bit platforms, which allows remote attackers to cause a denial of service (segmentation violation and application crash) or possibly have unspecified other impact via a crafted ELF file.
Affected Software
1 affected component
GNU binutils=2.29.1
Remediation
Patch Available
Event History
Nov 15, 2017
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-16830?
The severity of CVE-2017-16830 is rated high with a score of 7.8.
2
How do I fix CVE-2017-16830?
To fix CVE-2017-16830, upgrade GNU Binutils to version 2.29.2 or later.
3
What software is affected by CVE-2017-16830?
CVE-2017-16830 affects GNU Binutils version 2.29.1.
4
What type of vulnerability is CVE-2017-16830?
CVE-2017-16830 is classified as an integer overflow vulnerability.
5
What impact can CVE-2017-16830 have on systems?
CVE-2017-16830 can lead to denial of service, causing segmentation violations and application crashes.