Back

HIGH

binutils: Insuficient input validation in process_version_sections function in readelf.c

Published Sep 12, 2017

Description

The process_version_sections function in readelf.c in GNU Binutils 2.29 allows attackers to cause a denial of service (Integer Overflow, and hang because of a time-consuming loop) or possibly have unspecified other impact via a crafted binary file with invalid values of ent.vn_next, during "readelf -a" execution.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 12, 2017
Updated Aug 5, 2024
Reserved Sep 12, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Aug 29, 2017