CVE-2017-6969: Critical severity GNU binutils vulnerability
Last updated 24 July 2024
Other sources
readelf in GNU Binutils 2.28 is vulnerable to a heap-based buffer over-read while processing corrupt RL78 binaries. The vulnerability can trigger program crashes. It may lead to an information leak as well.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/binutilsto a version that resolves this vulnerability.Fixed in 2.35.2-2Fixed in 2.40-2Fixed in 2.44-3
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2017-6969.
What software is affected by this vulnerability?
The affected software is GNU Binutils version 2.28.
What is the impact of this vulnerability?
The vulnerability can trigger program crashes and may lead to an information leak.
How can I fix this vulnerability?
To fix this vulnerability, update to binutils version 2.28.3 or later.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability at the following references: [https://sourceware.org/bugzilla/show_bug.cgi?id=21156](https://sourceware.org/bugzilla/show_bug.cgi?id=21156), [http://www.securityfocus.com/bid/97065](http://www.securityfocus.com/bid/97065), and [https://security.gentoo.org/glsa/201709-02](https://security.gentoo.org/glsa/201709-02).