CVE-2017-9038: Medium severity GNU binutils vulnerability
GNU Binutils 2.28 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file, related to the bytegetlittleendian function in elfcomm.c, the getunwindsectionword function in readelf.c, and ARM unwind information that contains invalid word offsets.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2017-9038.
What is the title of this vulnerability?
The title of this vulnerability is 'GNU Binutils 2.28 allows remote attackers to cause a denial of service (heap-based buffer over-read ...'
What is the impact of this vulnerability?
This vulnerability can cause a denial of service (heap-based buffer over-read and application crash).
How can this vulnerability be exploited?
This vulnerability can be exploited by a remote attacker by using a crafted ELF file.
Which software versions are affected by this vulnerability?
GNU Binutils versions 2.26.1-1ubuntu1~16.04.8+ and 2.28-6 are affected.
How can I fix this vulnerability?
To fix this vulnerability, update GNU Binutils to version 2.31.1-16, 2.35.2-2, 2.40-2, or 2.41-5.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability at the following references: [Reference 1](https://blogs.gentoo.org/ago/2017/05/12/binutils-multiple-crashes/), [Reference 2](https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=f32ba72991d2406b21ab17edc234a2f3fa7fb23d), [Reference 3](http://www.securityfocus.com/bid/98589)