Red Hat Bugzilla – Bug 1500374
CVE-2017-15023 binutils: NULL pointer dereference in read_formatted_entries
Last modified: 2017-10-10 09:16:39 EDT
read_formatted_entries in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, does not properly validate the format count, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted ELF file, related to concat_filename. Upstream issue: https://sourceware.org/bugzilla/show_bug.cgi?id=22200 Upstream patch: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=c361faae8d964db951b7100cada4dcdc983df1bf
Created binutils tracking bugs for this issue: Affects: fedora-all [bug 1499311] Created mingw-binutils tracking bugs for this issue: Affects: epel-all [bug 1499310]