SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-7299

The vulnerability leads to a GNU linker (ld) program crash.

MEDIUM 5.5EPSS 1.13%

Does this matter?

Lower severity and a low EPSS score (1.13%). Track it; it rarely justifies an emergency change on its own.

Description

The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has an invalid read (of size 8) because the code to emit relocs (bfd_elf_final_link function in bfd/elflink.c) does not check the format of the input file before trying to read the ELF reloc section header. The vulnerability leads to a GNU linker (ld) program crash.

CVSS 3.0
5.5 MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS
1.13% probability · 64th percentile
CISA KEV
Not listed
Weakness
CWE-125
Affected
gnu/binutils
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.