CVE-2017-7224: Medium severity GNU binutils vulnerability
Last updated 24 July 2024
Other sources
The findnearestline function in objdump in GNU Binutils 2.28 is vulnerable to an invalid write (of size 1) while disassembling a corrupt binary that contains an empty function name, leading to a program crash.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/binutilsto a version that resolves this vulnerability.Fixed in 2.35.2-2Fixed in 2.40-2Fixed in 2.44-3 - Upgrade
Upgrade
GNU Binutils (objdump) find_nearest_lineto a version that resolves this vulnerability.Fixed in 2.28
Event History
Frequently Asked Questions
What is CVE-2017-7224?
CVE-2017-7224 is a vulnerability in the find_nearest_line function in objdump in GNU Binutils 2.28.
What is the impact of CVE-2017-7224?
CVE-2017-7224 can lead to an invalid write (of size 1) and a program crash when disassembling a corrupt binary with an empty function name.
Which software versions are affected by CVE-2017-7224?
GNU Binutils versions 2.28, 2.26.1-1ubuntu1~16.04.8+, 2.27.51.20161201-1, 2.31.1-16, 2.35.2-2, 2.40-2, and 2.41-5 are affected by CVE-2017-7224.
How can I fix CVE-2017-7224?
Upgrade to version 2.26.1-1ubuntu1~16.04.8+ or apply the patches provided by the respective software vendor.
Where can I find more information about CVE-2017-7224?
You can find more information about CVE-2017-7224 at the following references: [link1], [link2], [link3].