Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-6965

Опубликовано: 13 фев. 2017
Источник: redhat
CVSS3: 7
EPSS Низкий

Описание

readelf in GNU Binutils 2.28 writes to illegal addresses while processing corrupt input files containing symbol-difference relocations, leading to a heap-based buffer overflow.

A vulnerability was found in the readelf utility; part of binutils. A crafted ELF executable or shared library could cause readelf to write arbitrary locations on the heap while processing relocations, leading to a crash or potential code execution.

Отчет

Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5binutilsWill not fix
Red Hat Enterprise Linux 5binutils220Will not fix
Red Hat Enterprise Linux 6binutilsWill not fix
Red Hat Enterprise Linux 7binutilsWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1435640binutils: Heap-based buffer overflow in target_specific_reloc_handling in readelf

EPSS

Процентиль: 48%
0.00254
Низкий

7 High

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 9 лет назад

readelf in GNU Binutils 2.28 writes to illegal addresses while processing corrupt input files containing symbol-difference relocations, leading to a heap-based buffer overflow.

CVSS3: 5.5
nvd
почти 9 лет назад

readelf in GNU Binutils 2.28 writes to illegal addresses while processing corrupt input files containing symbol-difference relocations, leading to a heap-based buffer overflow.

CVSS3: 5.5
debian
почти 9 лет назад

readelf in GNU Binutils 2.28 writes to illegal addresses while process ...

CVSS3: 5.5
github
больше 3 лет назад

readelf in GNU Binutils 2.28 writes to illegal addresses while processing corrupt input files containing symbol-difference relocations, leading to a heap-based buffer overflow.

suse-cvrf
больше 7 лет назад

Security update for binutils

EPSS

Процентиль: 48%
0.00254
Низкий

7 High

CVSS3