Bug ID 1037066
Summary VUL-0: CVE-2017-8396: binutils: libbfd: heap buffer overflow in objdump
Classification openSUSE
Product openSUSE Distribution
Version Leap 42.2
Hardware Other
OS Other
Status NEW
Severity Normal
Priority P5 - None
Component Security
Assignee security-team@suse.de
Reporter mikhail.kasimov@gmail.com
QA Contact qa-bugs@suse.de
Found By ---
Blocker ---

Created attachment 723331 [details]
21432_upstream_crash_info

Ref: https://nvd.nist.gov/vuln/detail/CVE-2017-8396
====================================================
Description

The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU
Binutils 2.28, is vulnerable to an invalid read of size 1 because the existing
reloc offset range tests didn't catch small negative offsets less than the size
of the reloc field. This vulnerability causes programs that conduct an analysis
of binary programs using the libbfd library, such as objdump, to crash.
====================================================

Hyperlink

[1] https://sourceware.org/bugzilla/show_bug.cgi?id=21432

[2]
https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=a941291cab71b9ac356e1c03968c177c03e602ab
(see https://sourceware.org/bugzilla/show_bug.cgi?id=21432#c2)


(open-)SUSE: https://software.opensuse.org/package/binutils

2.28 (TW, official repo)
2.26.1 (42.{1,2}, official repo)


You are receiving this mail because: