CVE-2017-7301 PUBLISHED

The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has an aout_link_add_symbols function in bfd/aoutx.h that has an off-by-one vulnerability because it does not carefully check the string offset. The vulnerability could lead to a GNU linker (ld) program crash.

EPSS 0.41% · 60.8th percentile

Risk Scores

EPSS Score
0.41%
60.8th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:16.04:LTSbinutils*, 2.25.51.20151106-0ubuntu1, 2.25.51.20151113-1ubuntu1
Ubuntu:Pro:14.04:LTSbinutils2.23.90.20131017-1ubuntu1, 2.23.90.20131116-1ubuntu1, 2.24-1ubuntu1

Timeline

References

Open in Interactive Console →