CVE-2017-7304: High severity GNU binutils vulnerability
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid read (of size 8) because of missing a check (in the copyspecialsectionfields function) for an invalid shlink field before attempting to follow it. This vulnerability causes Binutils utilities like strip to crash.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7304?
CVE-2017-7304 has been assigned a medium severity level due to its potential to cause unexpected behavior in the GNU Binutils 2.28.
How do I fix CVE-2017-7304?
To fix CVE-2017-7304, you should update to a patched version of GNU Binutils that addresses the invalid read issue.
Which versions of GNU Binutils are affected by CVE-2017-7304?
CVE-2017-7304 affects GNU Binutils version 2.28 specifically.
What can happen if CVE-2017-7304 is exploited?
Exploitation of CVE-2017-7304 may lead to application crashes or unintended system behavior due to invalid memory reads.
Is CVE-2017-7304 related to the Binary File Descriptor library?
Yes, CVE-2017-7304 is a vulnerability specifically in the Binary File Descriptor (BFD) library within GNU Binutils.