CVE-2017-7299: Medium severity GNU binutils vulnerability
Last updated 24 July 2024
Other sources
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has an invalid read (of size 8) because the code to emit relocs (bfdelffinallink function in bfd/elflink.c) does not check the format of the input file before trying to read the ELF reloc section header. The vulnerability leads to a GNU linker (ld) program crash.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/binutilsto a version that resolves this vulnerability.Fixed in 2.35.2-2Fixed in 2.40-2Fixed in 2.44-3 - Upgrade
Upgrade
GNU Binutils libbfd (bfd/elflink.c)to a version that resolves this vulnerability.Fixed in 2.28
Event History
Frequently Asked Questions
What is CVE-2017-7299?
CVE-2017-7299 is a vulnerability in the Binary File Descriptor (BFD) library (aka libbfd) as distributed in GNU Binutils 2.28.
What is the severity of CVE-2017-7299?
The severity of CVE-2017-7299 is not mentioned in the provided information.
How does CVE-2017-7299 affect the affected software?
CVE-2017-7299 affects GNU Binutils versions 2.28, 2.26.1-1ubuntu1~16.04.8+, 2.27.51.20161220-1, 2.31.1-16, 2.35.2-2, 2.40-2, and 2.41-5.
What is the remedy for CVE-2017-7299?
The provided information does not specify a specific remedy for CVE-2017-7299.
Where can I find more information about CVE-2017-7299?
You can find more information about CVE-2017-7299 at the following references: https://sourceware.org/bugzilla/show_bug.cgi?id=20908, http://www.securityfocus.com/bid/97217, https://launchpad.net/bugs/cve/CVE-2017-7299.