CVE-2017-17080: Medium severity GNU binutils vulnerability
elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, does not validate sizes of core notes, which allows remote attackers to cause a denial of service (bfdgetl32 heap-based buffer over-read and application crash) via a crafted object file, related to elfcoregroknetbsdprocinfo, elfcoregrokopenbsdprocinfo, and elfcoregrokntostatus.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability CVE-2017-17080?
CVE-2017-17080 is a vulnerability in the Binary File Descriptor (BFD) library, as distributed in GNU Binutils 2.29.1, that allows remote attackers to cause a denial of service.
How does CVE-2017-17080 affect the affected software?
CVE-2017-17080 affects the Binutils package in Ubuntu versions 16.04.8 and later, as well as the Binutils package in Debian versions 2.31.1-16, 2.35.2-2, 2.40-2, and 2.41-5.
What is the severity of CVE-2017-17080?
The severity of CVE-2017-17080 is not specified.
How can I fix CVE-2017-17080?
To fix CVE-2017-17080, update the Binutils package to a version that includes the necessary security patches. Refer to the vendor's website for the appropriate updates.
Where can I find more information about CVE-2017-17080?
More information about CVE-2017-17080 can be found on the Sourceware Bugzilla and Gentoo Security websites.