ZeroHour

CVE-2017-16831

PoC
CVSS 3.0
7.8 high
EPSS
2%p77
Published
()
Modified
Description

coffgen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, does not validate the symbol count, which allows remote attackers to cause a denial of service (integer overflow and application crash, or excessive memory allocation) or possibly have unspecified other impact via a crafted PE file.

Vendors
gnu
Products
binutils
Weakness
CWE-190
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.