First published: Mon May 01 2017(Updated: )
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid read of size 8 because of missing a check to determine whether symbols are NULL in the _bfd_dwarf2_find_nearest_line function. This vulnerability causes programs that conduct an analysis of binary programs using the libbfd library, such as objdump, to crash.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Binutils | =2.28 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-8392 has been classified as a medium severity vulnerability.
To fix CVE-2017-8392, you should upgrade the GNU Binutils library to version 2.29 or later.
The impact of CVE-2017-8392 includes potential crashes or unintended behavior in applications using the affected BFD library.
CVE-2017-8392 affects GNU Binutils version 2.28.
Once exploited, the effects of CVE-2017-8392 may not be reversible without addressing the root cause through appropriate software updates.