Home CVE Database CVE-2017-8421

CVE-2017-8421

Description

The function coff_set_alignment_hook in coffcode.h in Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has a memory leak vulnerability which can cause memory exhaustion in objdump via a crafted PE file. Additional validation in dump_relocs_in_section in objdump.c can resolve this.

Priority: HIGH
CVSS v3: 5.5
Publish Date: May 2, 2017
Related ID: --
CVSS v2: Medium
Modified Date: May 12, 2017

Find out more about CVE-2017-8421 from the MITRE-CVE dictionary and NIST NVD


Products Affected

Login may be required to access defects or downloads.

Related Products

Product Name Status Defect Fixed Downloads
Linux 7 SCP Not Vulnerable -- -- --
Linux 7 CGP Not Vulnerable -- -- --

Comments

binutils

Live chat
Online