CVE-2017-9039
Published: 18 May 2017
GNU Binutils 2.28 allows remote attackers to cause a denial of service (memory consumption) via a crafted ELF file with many program headers, related to the get_program_headers function in readelf.c.
Priority
CVSS 3 base score: 5.5
Status
Package | Release | Status |
---|---|---|
binutils Launchpad, Ubuntu, Debian |
Upstream |
Released
(2.28-6)
|
Ubuntu 20.10 (Groovy Gorilla) |
Not vulnerable
(2.32-8ubuntu1)
|
|
Ubuntu 20.04 LTS (Focal Fossa) |
Not vulnerable
(2.32-8ubuntu1)
|
|
Ubuntu 18.04 LTS (Bionic Beaver) |
Not vulnerable
(2.30-21ubuntu1~18.04.1)
|
|
Ubuntu 16.04 LTS (Xenial Xerus) |
Needed
|
|
Ubuntu 14.04 ESM (Trusty Tahr) |
Needed
|
|
Patches: Upstream: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=82156ab704b08b124d319c0decdbd48b3ca2dac5 |