PT-2017-4320 · Gnu+1 · Gnu Binutils+1

CVE-2017-17122

·

Publicado

2017-11-28

·

Atualizado

2023-10-04

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: GNU Binutils version 2.29.1
Description: The issue is related to an integer overflow in the dump relocs in section function of the objdump.c component. This allows a remote attacker to cause a denial of service, potentially leading to excessive memory allocation or a heap-based buffer overflow, and application crash by using a specially crafted PE file. The attacker may also be able to access or modify confidential data.
Recommendations: For GNU Binutils version 2.29.1, consider disabling the dump relocs in section function as a temporary workaround until a patch is available. Restrict access to the objdump.c component to minimize the risk of exploitation. Avoid using specially crafted PE files that could trigger the integer overflow. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Integer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-07775
CVE-2017-17122
USN-5341-1
USN-6413-1

Produtos afetados

Gnu Binutils
Ubuntu