CVE-2017-17124: Buffer Overflow
Last updated 24 July 2024
Other sources
The bfdcoffreadstringtable function in coffgen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, does not properly validate the size of the external string table, which allows remote attackers to cause a denial of service (excessive memory consumption, or heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted COFF binary.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2017-17124.
What is the title of this vulnerability?
The title of this vulnerability is The _bfd_coff_read_string_table function in coffgen.c in the Binary File Descriptor (BFD) library.
What is the affected software for this vulnerability?
The affected software for this vulnerability is binutils version 2.26.1-1ubuntu1~16.04.8+ and binutils version 2.29.90.20180122-1.
How can this vulnerability be exploited?
This vulnerability can be exploited by remote attackers to cause a denial of service through excessive memory consumption.
What is the Common Weakness Enumeration (CWE) ID for this vulnerability?
The Common Weakness Enumeration (CWE) ID for this vulnerability is CWE-119.