CVE-2017-17080

Priority
Description
elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as
distributed in GNU Binutils 2.29.1, does not validate sizes of core notes,
which allows remote attackers to cause a denial of service (bfd_getl32
heap-based buffer over-read and application crash) via a crafted object
file, related to elfcore_grok_netbsd_procinfo,
elfcore_grok_openbsd_procinfo, and elfcore_grok_nto_status.
Package
Upstream:needs-triage
Ubuntu 12.04 ESM (Precise Pangolin):needs-triage
Trusty/esm:needs-triage
Ubuntu 16.04 LTS (Xenial Xerus):needs-triage
Ubuntu 18.04 LTS (Bionic Beaver):needs-triage
Ubuntu 18.10 (Cosmic Cuttlefish):needs-triage
Ubuntu 19.04 (Disco Dingo):needs-triage
Ubuntu 19.10 (Eoan):needs-triage
More Information

Updated: 2019-04-26 14:21:01 UTC (commit 30899e40836d26e1bb5f0b072d31fd87b6cf3bd4)