CVE-2017-17122: Integer Overflow
Last updated 24 July 2024
Other sources
The dumprelocsinsection function in objdump.c in GNU Binutils 2.29.1 does not check for reloc count integer overflows, which allows remote attackers to cause a denial of service (excessive memory allocation, or heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted PE file.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2017-17122?
CVE-2017-17122 is a vulnerability in the dump_relocs_in_section function in GNU Binutils 2.29.1 that allows attackers to cause a denial of service or possibly have other unspecified impacts.
What software is affected by CVE-2017-17122?
The affected software includes GNU Binutils version 2.29.1 and possibly other versions.
How can attackers exploit CVE-2017-17122?
Attackers can exploit this vulnerability to cause a denial of service by triggering excessive memory allocation, or by causing a heap-based buffer overflow and application crash.
How can I fix CVE-2017-17122?
To fix CVE-2017-17122, update to a version of GNU Binutils that is not affected by the vulnerability, such as version 2.26.1-1ubuntu1~16.04.8+.
Where can I find more information about CVE-2017-17122?
You can find more information about CVE-2017-17122 on the MITRE CVE database, Ubuntu security notices, and the NVD.