Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-6966

Опубликовано: 13 фев. 2017
Источник: redhat
CVSS3: 7
EPSS Низкий

Описание

readelf in GNU Binutils 2.28 has a use-after-free (specifically read-after-free) error while processing multiple, relocated sections in an MSP430 binary. This is caused by mishandling of an invalid symbol index, and mishandling of state across invocations.

A vulnerability was found in readelf; part of binutils. A crafted executable or shared library could cause use-after-free and out-of-bounds writes, leading to a crash or possible code execution.

Отчет

Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5binutilsWill not fix
Red Hat Enterprise Linux 5binutils220Will not fix
Red Hat Enterprise Linux 6binutilsWill not fix
Red Hat Enterprise Linux 7binutilsWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=1435646binutils: Use-after-free in target_specific_reloc_handling in readelf

EPSS

Процентиль: 51%
0.00278
Низкий

7 High

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 9 лет назад

readelf in GNU Binutils 2.28 has a use-after-free (specifically read-after-free) error while processing multiple, relocated sections in an MSP430 binary. This is caused by mishandling of an invalid symbol index, and mishandling of state across invocations.

CVSS3: 5.5
nvd
почти 9 лет назад

readelf in GNU Binutils 2.28 has a use-after-free (specifically read-after-free) error while processing multiple, relocated sections in an MSP430 binary. This is caused by mishandling of an invalid symbol index, and mishandling of state across invocations.

CVSS3: 5.5
debian
почти 9 лет назад

readelf in GNU Binutils 2.28 has a use-after-free (specifically read-a ...

CVSS3: 5.5
github
больше 3 лет назад

readelf in GNU Binutils 2.28 has a use-after-free (specifically read-after-free) error while processing multiple, relocated sections in an MSP430 binary. This is caused by mishandling of an invalid symbol index, and mishandling of state across invocations.

suse-cvrf
больше 7 лет назад

Security update for binutils

EPSS

Процентиль: 51%
0.00278
Низкий

7 High

CVSS3