Invalid Read Vulnerability in GNU Binutils 2.28

Invalid Read Vulnerability in GNU Binutils 2.28

CVE-2017-7304 · MEDIUM Severity

AV:N/AC:L/AU:N/C:N/I:N/A:P

The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid read (of size 8) because of missing a check (in the copy_special_section_fields function) for an invalid sh_link field before attempting to follow it. This vulnerability causes Binutils utilities like strip to crash.

Learn more about our Web Application Penetration Testing UK.