Back

MEDIUM

binutils: out of bounds read in elf_parse_notes function in elf.c file in libbfd library

Published Feb 9, 2018

Description

The elf_parse_notes function in elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to cause a denial of service (out-of-bounds read and segmentation violation) via a note with a large alignment.

Affected products

Remediation

Red Hat statement

The prerequisites for successful exploitation of this bug involves both independent filesystem access as well as the victim to interact with the file created. * An attacker needs to create a file (such as an ELF file) containing a note section with a large alignment value designed to trigger the out-of-bounds read in the elf_parse_notes function. * The attacker must convince a user to process the malicious file using a tool that utilizes the vulnerable libbfd library, such as objdump or readelf. Considering the high bar of prerequites for successful exploitation, RH ProdSec has set the Impact of this vulnerability to "Low"

Metrics

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 9, 2018
Updated Aug 5, 2024
Reserved Feb 9, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Feb 5, 2018