CVE-2017-9954: Medium severity binutils vulnerability
Last updated 24 July 2024
Other sources
The getvalue function in tekhex.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a crafted tekhex file, as demonstrated by mishandling within the nm program.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2017-9954.
What is the title of this vulnerability?
The title of this vulnerability is 'The getvalue function in tekhex.c in the Binary File Descriptor (BFD) library (aka libbfd) as distri…'
What is the affected software for this vulnerability?
The affected software for this vulnerability is GNU Binutils 2.28.
How can a remote attacker exploit this vulnerability?
A remote attacker can exploit this vulnerability by using a crafted tekhex file.
Is there a fix available for this vulnerability?
Yes, there are fixes available for this vulnerability. Please refer to the provided references for more information.