GNU Binutils CVE-2017-15996 Multiple Denial of Service Vulnerabilities
BID:101608
Info
GNU Binutils CVE-2017-15996 Multiple Denial of Service Vulnerabilities
| Bugtraq ID: | 101608 |
| Class: | Input Validation Error |
| CVE: |
CVE-2017-15996 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 29 2017 12:00AM |
| Updated: | Dec 19 2017 10:00PM |
| Credit: | Kirit Sankar Gupta |
| Vulnerable: |
GNU Binutils 2.29 |
| Not Vulnerable: | |
Discussion
GNU Binutils CVE-2017-15996 Multiple Denial of Service Vulnerabilities
GNU Binutils is prone to multiple denial-of-service vulnerabilities.
An attacker can exploit these issues to cause a denial-of-service condition.
GNU Binutils 2.29 is vulnerable; other versions may also be affected.
GNU Binutils is prone to multiple denial-of-service vulnerabilities.
An attacker can exploit these issues to cause a denial-of-service condition.
GNU Binutils 2.29 is vulnerable; other versions may also be affected.
Exploit / POC
GNU Binutils CVE-2017-15996 Multiple Denial of Service Vulnerabilities
The researcher who discovered this issue has created a proof-of-concept. Please see the references for more information.
The researcher who discovered this issue has created a proof-of-concept. Please see the references for more information.
Solution / Fix
GNU Binutils CVE-2017-15996 Multiple Denial of Service Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
GNU Binutils CVE-2017-15996 Multiple Denial of Service Vulnerabilities
References:
References:
- Bug 22361 - Memory Allocation Error stemming from a Conditional jump dependant o (sourceware.org)
- GNU Homepage (binutils)
- PR22361 readelf buffer overflow on fuzzed archive header (sourceware.org)