Vulnerability Description
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has a swap_std_reloc_out function in bfd/aoutx.h that is vulnerable to an invalid read (of size 4) because of missing checks for relocs that could not be recognised. This vulnerability causes Binutils utilities like strip to crash.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gnu | Binutils | 2.28 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/97216PatchVDB Entry
- https://sourceware.org/bugzilla/show_bug.cgi?id=20921Issue TrackingPatch
- http://www.securityfocus.com/bid/97216PatchVDB Entry
- https://sourceware.org/bugzilla/show_bug.cgi?id=20921Issue TrackingPatch
FAQ
What is CVE-2017-7302?
CVE-2017-7302 is a vulnerability with a CVSS score of 7.5 (HIGH). The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has a swap_std_reloc_out function in bfd/aoutx.h that is vulnerable to an invalid read (of size 4) because o...
How severe is CVE-2017-7302?
CVE-2017-7302 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-7302?
Check the references section above for vendor advisories and patch information. Affected products include: Gnu Binutils.