CVE-2017-17080

Priority
Description
elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as
distributed in GNU Binutils 2.29.1, does not validate sizes of core notes,
which allows remote attackers to cause a denial of service (bfd_getl32
heap-based buffer over-read and application crash) via a crafted object
file, related to elfcore_grok_netbsd_procinfo,
elfcore_grok_openbsd_procinfo, and elfcore_grok_nto_status.
Package
Upstream:needs-triage
Ubuntu 12.04 ESM (Precise Pangolin):needs-triage
Ubuntu 14.04 LTS (Trusty Tahr):needs-triage
Ubuntu 16.04 LTS (Xenial Xerus):needs-triage
Ubuntu 18.04 LTS (Bionic Beaver):needs-triage
Ubuntu 18.10 (Cosmic Cuttlefish):needs-triage
Ubuntu 19.04 (Disco Dingo):needs-triage
More Information

Updated: 2019-01-14 21:24:56 UTC (commit 51f9b73af244ba86b9321e46e526586c25a8e060)