Heap-based buffer over-read vulnerability in bfd_get_debug_link_info_1 in libbfd allows for denial of service

Heap-based buffer over-read vulnerability in bfd_get_debug_link_info_1 in libbfd allows for denial of service

CVE-2017-15021 · MEDIUM Severity

AV:N/AC:M/AU:N/C:N/I:N/A:P

bfd_get_debug_link_info_1 in opncls.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file, related to bfd_getl32.

Learn more about our Web Application Penetration Testing UK.