NULL pointer dereference and invalid write vulnerability in GNU Binutils 2.28's addr2line function

NULL pointer dereference and invalid write vulnerability in GNU Binutils 2.28's addr2line function

CVE-2017-7225 · MEDIUM Severity

AV:N/AC:L/AU:N/C:N/I:N/A:P

The find_nearest_line function in addr2line in GNU Binutils 2.28 does not handle the case where the main file name and the directory name are both empty, triggering a NULL pointer dereference and an invalid write, and leading to a program crash.

Learn more about our Web Application Penetration Testing UK.