Vulnerability Description
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid read (of size 4) because of missing a check (in the find_link function) for null headers before attempting to match them. This vulnerability causes Binutils utilities like strip to crash.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gnu | Binutils | 2.28 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/97213Third Party AdvisoryVDB Entry
- https://sourceware.org/bugzilla/show_bug.cgi?id=20922Issue TrackingPatch
- http://www.securityfocus.com/bid/97213Third Party AdvisoryVDB Entry
- https://sourceware.org/bugzilla/show_bug.cgi?id=20922Issue TrackingPatch
FAQ
What is CVE-2017-7303?
CVE-2017-7303 is a vulnerability with a CVSS score of 7.5 (HIGH). The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid read (of size 4) because of missing a check (in the find_link function) for null...
How severe is CVE-2017-7303?
CVE-2017-7303 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-7303?
Check the references section above for vendor advisories and patch information. Affected products include: Gnu Binutils.