GNU Binutils 'bfd/vms-alpha.c' Remote Buffer Overflow Vulnerability



GNU Binutils is prone to a remote buffer-overflow vulnerability because it fails to adequately bounds-check user-supplied data before copying it to an insufficiently sized memory buffer.

An attacker can exploit this issue to crash the affected application, resulting in denial-of-service conditions. Due to the nature of this issue, arbitrary code execution may be possible but this has not been confirmed.

GNU Binutils 2.28 is vulnerable; other versions may also be affected.

Information

Bugtraq ID: 99122
Class: Boundary Condition Error
CVE: CVE-2017-9752

Remote: Yes
Local: No
Published: Jun 19 2017 12:00AM
Updated: Jun 19 2017 12:00AM
Credit: Alexandre Adamski
Vulnerable: GNU Binutils 2.28


Not Vulnerable:

Exploit


The researcher who discovered this issue has created a proof-of-concept. Please see the references for more information.


Related Posts