CVE-2017-7300: High severity GNU binutils vulnerability
Last updated 24 July 2024
Other sources
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has an aoutlinkaddsymbols function in bfd/aoutx.h that is vulnerable to a heap-based buffer over-read (off-by-one) because of an incomplete check for invalid string offsets while loading symbols, leading to a GNU linker (ld) program crash.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/binutilsto a version that resolves this vulnerability.Fixed in 2.35.2-2Fixed in 2.40-2Fixed in 2.44-3 - Upgrade
Upgrade
GNU Binutils (libbfd/libbfd aout_link_add_symbols)to a version that resolves this vulnerability.Fixed in 2.28
Event History
Frequently Asked Questions
What is CVE-2017-7300?
CVE-2017-7300 is a vulnerability in the Binary File Descriptor (BFD) library (libbfd) as distributed in GNU Binutils 2.28.
How does CVE-2017-7300 impact my system?
CVE-2017-7300 can lead to a heap-based buffer over-read (off-by-one) when loading symbols, potentially causing a denial of service or information disclosure.
Which software versions are affected by CVE-2017-7300?
CVE-2017-7300 affects GNU Binutils 2.28.
How can I fix CVE-2017-7300?
To fix CVE-2017-7300, update your GNU Binutils installation to version 2.26.1-1ubuntu1~16.04.8+ or apply the appropriate patches provided by your software vendor.
Where can I find more information about CVE-2017-7300?
You can find more information about CVE-2017-7300 at the following references: [1] [2] [3].