[Secure-testing-team] Bug#859989: binutils: CVE-2017-7614

Salvatore Bonaccorso carnil at debian.org
Mon Apr 10 04:20:52 UTC 2017


Source: binutils
Version: 2.28-3
Severity: normal
Tags: patch upstream security

Hi,

the following vulnerability was published for binutils.

CVE-2017-7614[0]:
| elflink.c in the Binary File Descriptor (BFD) library (aka libbfd), as
| distributed in GNU Binutils 2.28, has a "member access within null
| pointer" undefined behavior issue, which might allow remote attackers
| to cause a denial of service (application crash) or possibly have
| unspecified other impact via an "int main() {return 0;}" program.

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2017-7614
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-7614
[1] https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;a=commitdiff;h=ad32986fdf9da1c8748e47b8b45100398223dba8

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore



More information about the Secure-testing-team mailing list