CVE-2017-7302: High severity GNU binutils vulnerability
Last updated 24 July 2024
Other sources
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has a swapstdrelocout function in bfd/aoutx.h that is vulnerable to an invalid read (of size 4) because of missing checks for relocs that could not be recognised. This vulnerability causes Binutils utilities like strip to crash.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/binutilsto a version that resolves this vulnerability.Fixed in 2.35.2-2Fixed in 2.40-2Fixed in 2.44-3
Event History
Frequently Asked Questions
What is CVE-2017-7302?
CVE-2017-7302 is a vulnerability in the Binary File Descriptor (BFD) library that is distributed in GNU Binutils 2.28.
How does the vulnerability in CVE-2017-7302 occur?
The vulnerability occurs due to a missing check for relocs that could not be recognized, leading to an invalid read of size 4.
What is the severity of CVE-2017-7302?
The severity of CVE-2017-7302 is not specified.
How can I fix CVE-2017-7302?
To fix CVE-2017-7302, you should update GNU Binutils to version 2.27.51.20161212-1 or later.
Where can I find more information about CVE-2017-7302?
You can find more information about CVE-2017-7302 at the following references: [1] [2] [3].