Back

HIGH

binutils: Out-of-bounds read due to wrong assumption for objcopy and strip

Published May 1, 2017

Description

The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to a global buffer over-read error because of an assumption made by code that runs for objcopy and strip, that SHT_REL/SHR_RELA sections are always named starting with a .rel/.rela prefix. This vulnerability causes programs that conduct an analysis of binary programs using the libbfd library, such as objcopy and strip, to crash.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 1, 2017
Updated Aug 5, 2024
Reserved May 1, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Apr 22, 2017