First published: Sun Apr 09 2017(Updated: )
elflink.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has a "member access within null pointer" undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via an "int main() {return 0;}" program.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNU Binutils | =2.28 | |
debian/binutils | 2.35.2-2 2.40-2 2.43.1-5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The CVE ID of this vulnerability is CVE-2017-7614.
The affected software for this vulnerability is GNU Binutils.
The severity of CVE-2017-7614 is not specified.
Remote attackers can exploit CVE-2017-7614 to cause a denial of service (application crash) or possibly have unspecified other impact.
To remediate CVE-2017-7614, update GNU Binutils to version 2.26.1-1ubuntu1~16.04.8+ or apply the necessary updates from the respective package repositories.