CVE-2017-16832

MEDIUM

Description

The pe_bfd_read_buildid function in peicode.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, does not validate size and offset values in the data dictionary, which allows remote attackers to cause a denial of service (segmentation violation and application crash) or possibly have unspecified other impact via a crafted PE file.

References

https://security.gentoo.org/glsa/201811-17

https://sourceware.org/bugzilla/show_bug.cgi?id=22373

https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=0bb6961f18b8e832d88b490d421ca56cea16c45b

Details

Source: MITRE

Published: 2017-11-15

Updated: 2018-11-27

Type: CWE-190

Risk Information

CVSS v2.0

Base Score: 6.8

Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 8.6

Severity: MEDIUM

CVSS v3.0

Base Score: 7.8

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 1.8

Severity: HIGH

Vulnerable Software

Configuration 1

OR

cpe:2.3:a:gnu:binutils:2.29.1:*:*:*:*:*:*:*

Tenable Plugins

View all (14 total)

IDNameProductFamilySeverity
135628EulerOS Virtualization 3.0.2.2 : binutils (EulerOS-SA-2020-1466)NessusHuawei Local Security Checks
high
134494EulerOS Virtualization for ARM 64 3.0.2.0 : binutils (EulerOS-SA-2020-1205)NessusHuawei Local Security Checks
medium
130838EulerOS 2.0 SP5 : binutils (EulerOS-SA-2019-2129)NessusHuawei Local Security Checks
medium
123342openSUSE Security Update : binutils (openSUSE-2019-808)NessusSuSE Local Security Checks
medium
121791Photon OS 2.0: Binutils PHSA-2017-2.0-0008NessusPhotonOS Local Security Checks
medium
120133SUSE SLED15 / SLES15 Security Update : binutils (SUSE-SU-2018:3170-2)NessusSuSE Local Security Checks
medium
120132SUSE SLED15 / SLES15 Security Update : binutils (SUSE-SU-2018:3170-1)NessusSuSE Local Security Checks
medium
119162GLSA-201811-17 : Binutils: Multiple vulnerabilitiesNessusGentoo Local Security Checks
medium
118337openSUSE Security Update : binutils (openSUSE-2018-1222)NessusSuSE Local Security Checks
medium
118303SUSE SLES12 Security Update : binutils (SUSE-SU-2018:3207-2)NessusSuSE Local Security Checks
high
118220openSUSE Security Update : binutils (openSUSE-2018-1198)NessusSuSE Local Security Checks
high
118199SUSE SLED12 / SLES12 Security Update : binutils (SUSE-SU-2018:3207-1)NessusSuSE Local Security Checks
high
111906Photon OS 2.0: Binutils / Linux / Wget PHSA-2017-2.0-0008 (deprecated)NessusPhotonOS Local Security Checks
medium
111901Photon OS 1.0: Binutils / Glibc / Linux / Mongodb / Openssh / Procmail / Python2 / Rsync PHSA-2017-0052 (deprecated)NessusPhotonOS Local Security Checks
critical