CVE-2017-17125

high
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

nm.c and objdump.c in GNU Binutils 2.29.1 mishandle certain global symbols, which allows remote attackers to cause a denial of service (_bfd_elf_get_symbol_version_string buffer over-read and application crash) or possibly have unspecified other impact via a crafted ELF file.

References

https://security.gentoo.org/glsa/201811-17

https://sourceware.org/bugzilla/show_bug.cgi?id=22443

https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=160b1a618ad94988410dc81fce9189fcda5b7ff4

Details

Source: MITRE

Published: 2017-12-04

Updated: 2019-10-03

Type: CWE-125

Risk Information

CVSS v2

Base Score: 6.8

Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 8.6

Severity: MEDIUM

CVSS v3

Base Score: 7.8

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Impact Score: 5.9

Exploitability Score: 1.8

Severity: HIGH

Vulnerable Software

Configuration 1

OR

cpe:2.3:a:gnu:binutils:2.29.1:*:*:*:*:*:*:*

Tenable Plugins

View all (9 total)

IDNameProductFamilySeverity
151919Ubuntu 16.04 LTS : GNU binutils vulnerabilities (USN-4336-2)NessusUbuntu Local Security Checks
critical
135628EulerOS Virtualization 3.0.2.2 : binutils (EulerOS-SA-2020-1466)NessusHuawei Local Security Checks
critical
134494EulerOS Virtualization for ARM 64 3.0.2.0 : binutils (EulerOS-SA-2020-1205)NessusHuawei Local Security Checks
high
130838EulerOS 2.0 SP5 : binutils (EulerOS-SA-2019-2129)NessusHuawei Local Security Checks
high
121791Photon OS 2.0: Binutils PHSA-2017-2.0-0008NessusPhotonOS Local Security Checks
high
121783Photon OS 1.0: Binutils PHSA-2017-1.0-0095NessusPhotonOS Local Security Checks
critical
119162GLSA-201811-17 : Binutils: Multiple vulnerabilitiesNessusGentoo Local Security Checks
high
111906Photon OS 2.0: Binutils / Linux / Wget PHSA-2017-2.0-0008 (deprecated)NessusPhotonOS Local Security Checks
high
111904Photon OS 1.0: Binutils / Curl / Docker / Linux / Rpm PHSA-2017-1.0-0095 (deprecated)NessusPhotonOS Local Security Checks
critical