CVE-2017-8397: Buffer Overflow
Last updated 24 July 2024
Other sources
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid read of size 1 and an invalid write of size 1 during processing of a corrupt binary containing reloc(s) with negative addresses. This vulnerability causes programs that conduct an analysis of binary programs using the libbfd library, such as objdump, to crash.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2017-8397?
CVE-2017-8397 is a vulnerability in the Binary File Descriptor (BFD) library, as distributed in GNU Binutils 2.28.
What is the severity of CVE-2017-8397?
The severity of CVE-2017-8397 is not specified in the provided information.
How does CVE-2017-8397 manifest?
CVE-2017-8397 manifests as an invalid read of size 1 and an invalid write of size 1 during the processing of a corrupt binary containing reloc(s) with negative addresses.
What software is affected by CVE-2017-8397?
The affected software is GNU Binutils versions 2.28, 2.26.1-1ubuntu1~16.04.8+, and versions 2.31.1-16, 2.35.2-2, 2.40-2, and 2.41-5 of the Debian binutils package.
How can I mitigate CVE-2017-8397?
To mitigate CVE-2017-8397, users should update to the specified fixed versions of the affected software.