CVE-2017-9745: Buffer Overflow
Last updated 24 July 2024
Other sources
The bfdvmsslurpetir function in bfd/vms-alpha.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by mishandling of this file during "objdump -D" execution.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-9745?
The severity of CVE-2017-9745 is high.
How does CVE-2017-9745 affect the Binary File Descriptor (BFD) library?
CVE-2017-9745 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact on the Binary File Descriptor (BFD) library.
Which software is affected by CVE-2017-9745?
The affected software is GNU Binutils 2.28, Ubuntu binutils 2.29-1, Ubuntu binutils 2.26.1-1ubuntu1~16.04.8+, and Debian binutils 2.31.1-16, 2.35.2-2, 2.40-2, and 2.41-5.
How can I fix CVE-2017-9745?
To fix CVE-2017-9745, update to Ubuntu binutils 2.29-1 or higher, Ubuntu binutils 2.26.1-1ubuntu1~16.04.8+ or higher, or Debian binutils 2.31.1-16, 2.35.2-2, 2.40-2, or 2.41-5.
Where can I find more information about CVE-2017-9745?
You can find more information about CVE-2017-9745 on the following references: [sourceware.org](https://sourceware.org/bugzilla/show_bug.cgi?id=21579), [securityfocus.com](http://www.securityfocus.com/bid/99109), [launchpad.net](https://launchpad.net/bugs/cve/CVE-2017-9745).