Back

CRITICAL

binutils: Heap-based buffer over-read in pe_ILF_object_p function in libbfd

Published Mar 22, 2017

Description

The pe_ILF_object_p function in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to a heap-based buffer over-read of size 4049 because it uses the strlen function instead of strnlen, leading to program crashes in several utilities such as addr2line, size, and strings. It could lead to information disclosure as well.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 22, 2017
Updated Sep 16, 2024
Reserved Mar 22, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Dec 1, 2016