VDB
CVE-2017-17124
CVE-2017-17124
PUBLISHED
CVSS 7.800000190734863 HIGH
The _bfd_coff_read_string_table function in coffgen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, does not properly validate the size of the external string table, which allows remote attackers to cause a denial of service (excessive memory consumption, or heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted COFF binary.
EPSS 2.95% · 86.1th percentile
Risk Scores
CVSS 3.0
7.800000190734863
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
2.95%
86.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:Pro:16.04:LTS | binutils | 0, 2.25.1-6ubuntu1, 2.25.51.20151022-0ubuntu3 |
| Ubuntu:Pro:14.04:LTS | binutils | 2.23.52.20130913-0ubuntu1, 2.23.90.20131017-1ubuntu1, 2.23.90.20131116-1ubuntu1 |
Timeline
- Dec 4, 2017 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Feb 28, 2022 EPSS Score
- May 2, 2022 EPSS Score
- Jul 4, 2022 EPSS Score
- Sep 6, 2022 EPSS Score
- Nov 7, 2022 EPSS Score
- Jan 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
References
- https://ubuntu.com/security/CVE-2017-17124 third-party-advisory
- https://ubuntu.com/security/notices/USN-4336-2 vendor-advisory
- https://www.cve.org/CVERecord?id=CVE-2017-17124 third-party-advisory