CVE-2017-16832: Integer Overflow
Last updated 24 July 2024
Other sources
The pebfdreadbuildid function in peicode.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, does not validate size and offset values in the data dictionary, which allows remote attackers to cause a denial of service (segmentation violation and application crash) or possibly have unspecified other impact via a crafted PE file.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2017-16832?
CVE-2017-16832 is a vulnerability in the Binary File Descriptor (BFD) library, as distributed in GNU Binutils 2.29.1.
How does CVE-2017-16832 affect me?
CVE-2017-16832 allows remote attackers to cause a denial of service (segmentation violation and application crash).
What software is affected by CVE-2017-16832?
The affected software includes Ubuntu Binutils 2.29.90.20180122-1, Binutils 2.26.1-1ubuntu1~16.04.8+, and Debian Binutils versions 2.31.1-16, 2.35.2-2, 2.40-2, and 2.41-5.
How can I fix CVE-2017-16832?
To fix CVE-2017-16832, update the affected software to Ubuntu Binutils 2.29.90.20180122-1 or Binutils 2.26.1-1ubuntu1~16.04.8+ (for Ubuntu), or update to one of the fixed Debian Binutils versions.
Where can I find more information about CVE-2017-16832?
More information about CVE-2017-16832 can be found at the following references: [sourceware.org/bugzilla/show_bug.cgi?id=22373](sourceware.org/bugzilla/show_bug.cgi?id=22373), [sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=0bb6961f18b8e832d88b490d421ca56cea16c45b](sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=0bb6961f18b8e832d88b490d421ca56cea16c45b), [security.gentoo.org/glsa/201811-17](security.gentoo.org/glsa/201811-17).