CVE-2017-7225: Null Pointer Dereference
Last updated 24 July 2024
Other sources
The findnearestline function in addr2line in GNU Binutils 2.28 does not handle the case where the main file name and the directory name are both empty, triggering a NULL pointer dereference and an invalid write, and leading to a program crash.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/binutilsto a version that resolves this vulnerability.Fixed in 2.35.2-2Fixed in 2.40-2Fixed in 2.44-3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.28
Event History
Frequently Asked Questions
What is CVE-2017-7225?
CVE-2017-7225 is a vulnerability in GNU Binutils 2.28 that allows for a NULL pointer dereference and an invalid write, leading to a program crash.
What is the severity of CVE-2017-7225?
The severity of CVE-2017-7225 is not specified in the given information.
How does CVE-2017-7225 affect software?
CVE-2017-7225 affects GNU Binutils 2.28 and may result in a program crash.
How can I fix CVE-2017-7225?
To fix CVE-2017-7225, update your GNU Binutils version to 2.31.1-16 or higher.
Where can I find more information about CVE-2017-7225?
You can find more information about CVE-2017-7225 at the following references: [Sourceware Bugzilla](https://sourceware.org/bugzilla/show_bug.cgi?id=20891), [SecurityFocus](http://www.securityfocus.com/bid/97275), [Gentoo GLSA](https://security.gentoo.org/glsa/201801-01).