CVE-2017-7223: Buffer Overflow
GNU assembler in GNU Binutils 2.28 is vulnerable to a global buffer overflow (of size 1) while attempting to unget an EOF character from the input stream, potentially leading to a program crash.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/binutilsto a version that resolves this vulnerability.Fixed in 2.35.2-2Fixed in 2.40-2Fixed in 2.44-3
Event History
Frequently Asked Questions
What is CVE-2017-7223?
CVE-2017-7223 is a vulnerability in the GNU assembler in GNU Binutils 2.28 that allows a global buffer overflow, potentially causing a program crash.
What is the severity of CVE-2017-7223?
The severity of CVE-2017-7223 is not specified.
How does CVE-2017-7223 affect GNU Binutils?
CVE-2017-7223 affects GNU Binutils 2.28 and potentially other versions.
How can I fix CVE-2017-7223?
To fix CVE-2017-7223, upgrade to a version of GNU Binutils specified by the vendor.
Where can I find more information about CVE-2017-7223?
You can find more information about CVE-2017-7223 in the references provided: [sourceware.org](https://sourceware.org/bugzilla/show_bug.cgi?id=20898), [security.gentoo.org](https://security.gentoo.org/glsa/201801-01), [launchpad.net](https://launchpad.net/bugs/cve/CVE-2017-7223).