CVE-2017-7301: Input Validation
Last updated 24 July 2024
Other sources
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has an aoutlinkaddsymbols function in bfd/aoutx.h that has an off-by-one vulnerability because it does not carefully check the string offset. The vulnerability could lead to a GNU linker (ld) program crash.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/binutilsto a version that resolves this vulnerability.Fixed in 2.35.2-2Fixed in 2.40-2Fixed in 2.44-3
Event History
Frequently Asked Questions
What is CVE-2017-7301?
CVE-2017-7301 is a vulnerability in the Binary File Descriptor (BFD) library as distributed in GNU Binutils 2.28.
What is the severity of CVE-2017-7301?
The severity of CVE-2017-7301 is not specified in the information provided.
How does CVE-2017-7301 affect the affected software?
CVE-2017-7301 affects the binutils package in Ubuntu (version 2.26.1-1ubuntu1~16.04.8+ and version 2.27.51.20161212-1) and binutils package in Debian (versions 2.31.1-16, 2.35.2-2, 2.40-2, 2.41-5).
How can I fix CVE-2017-7301?
To fix CVE-2017-7301, apply the recommended updates provided by the Ubuntu or Debian security team.
Where can I find more information about CVE-2017-7301?
You can find more information about CVE-2017-7301 at the following references: [link1](https://sourceware.org/bugzilla/show_bug.cgi?id=20924), [link2](http://www.securityfocus.com/bid/97218), [link3](https://launchpad.net/bugs/cve/CVE-2017-7301).