VulnerabilityModified
CVE-2017-7299
The vulnerability leads to a GNU linker (ld) program crash.
MEDIUM 5.5EPSS 1.13%
Does this matter?
Lower severity and a low EPSS score (1.13%). Track it; it rarely justifies an emergency change on its own.
Description
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has an invalid read (of size 8) because the code to emit relocs (bfd_elf_final_link function in bfd/elflink.c) does not check the format of the input file before trying to read the ELF reloc section header. The vulnerability leads to a GNU linker (ld) program crash.
- CVSS 3.0
- 5.5 MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- EPSS
- 1.13% probability · 64th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-125
- Affected
- gnu/binutils
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/bid/97217Third Party Advisory, VDB Entry
- https://sourceware.org/bugzilla/show_bug.cgi?id=20908Issue Tracking, Patch
- http://www.securityfocus.com/bid/97217Third Party Advisory, VDB Entry
- https://sourceware.org/bugzilla/show_bug.cgi?id=20908Issue Tracking, Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.