Vulnerability Description
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid read (of size 8) because of missing a check (in the copy_special_section_fields function) for an invalid sh_link field before attempting to follow it. This vulnerability causes Binutils utilities like strip to crash.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gnu | Binutils | 2.28 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/97215Third Party AdvisoryVDB Entry
- https://sourceware.org/bugzilla/show_bug.cgi?id=20931Issue TrackingPatch
- http://www.securityfocus.com/bid/97215Third Party AdvisoryVDB Entry
- https://sourceware.org/bugzilla/show_bug.cgi?id=20931Issue TrackingPatch
FAQ
What is CVE-2017-7304?
CVE-2017-7304 is a vulnerability with a CVSS score of 7.5 (HIGH). The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid read (of size 8) because of missing a check (in the copy_special_section_fields ...
How severe is CVE-2017-7304?
CVE-2017-7304 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-7304?
Check the references section above for vendor advisories and patch information. Affected products include: Gnu Binutils.