CVE-2017-7227: Buffer Overflow
GNU linker (ld) in GNU Binutils 2.28 is vulnerable to a heap-based buffer overflow while processing a bogus input script, leading to a program crash. This relates to lack of '\0' termination of a name field in ldlex.l.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/binutilsto a version that resolves this vulnerability.Fixed in 2.35.2-2Fixed in 2.40-2Fixed in 2.44-3
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7227?
The severity of CVE-2017-7227 is high.
How does the vulnerability in CVE-2017-7227 occur?
The vulnerability in CVE-2017-7227 occurs due to a heap-based buffer overflow while processing a bogus input script.
What is the impact of the vulnerability in CVE-2017-7227?
The vulnerability in CVE-2017-7227 can lead to a program crash.
How can I fix the vulnerability in CVE-2017-7227?
To fix the vulnerability in CVE-2017-7227, update the affected GNU Binutils package to version 2.26.1-1ubuntu1~16.04.8+ or later.
Where can I find more information about CVE-2017-7227?
You can find more information about CVE-2017-7227 at the following references: [sourceware.org](https://sourceware.org/bugzilla/show_bug.cgi?id=20906), [securityfocus.com](http://www.securityfocus.com/bid/97209), [security.gentoo.org](https://security.gentoo.org/glsa/201801-01).