CVE-2017-16832
Published: 15 November 2017
The pe_bfd_read_buildid function in peicode.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, does not validate size and offset values in the data dictionary, which allows remote attackers to cause a denial of service (segmentation violation and application crash) or possibly have unspecified other impact via a crafted PE file.
Priority
CVSS 3 base score: 7.8
Status
Package | Release | Status |
---|---|---|
binutils Launchpad, Ubuntu, Debian |
Upstream |
Released
(2.29.90.20180122-1)
|
Ubuntu 20.10 (Groovy Gorilla) |
Not vulnerable
(2.30-21ubuntu1~18.04)
|
|
Ubuntu 20.04 LTS (Focal Fossa) |
Not vulnerable
(2.30-21ubuntu1~18.04)
|
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Not vulnerable
(2.30-21ubuntu1~18.04)
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Needed
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Needed
|
|
Patches: Upstream: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=0bb6961f18b8e832d88b490d421ca56cea16c45b |