CVE-2017-7226

Source
https://cve.org/CVERecord?id=CVE-2017-7226
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-7226.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2017-7226
Downstream
Related
Published
2017-03-22T16:59:00.260Z
Modified
2026-07-08T16:53:29.967865Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H CVSS Calculator
Summary
[none]
Details

The peILFobject_p function in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to a heap-based buffer over-read of size 4049 because it uses the strlen function instead of strnlen, leading to program crashes in several utilities such as addr2line, size, and strings. It could lead to information disclosure as well.

References

Affected packages

Git / sourceware.org/git/binutils-gdb.git

Affected ranges

Type
GIT
Repo
https://sourceware.org/git/binutils-gdb.git
Events
Introduced
7fa393306ed8b93019d225548474c0540b8928f7
Last affected
7fa393306ed8b93019d225548474c0540b8928f7
Database specific
{
    "extracted_events": [
        {
            "introduced": "2.28"
        },
        {
            "last_affected": "2.28"
        }
    ],
    "source": "CPE_STRING",
    "cpe": "cpe:2.3:a:gnu:binutils:2.28:*:*:*:*:*:*:*"
}

Affected versions

2.*
2.28
Other
binutils-2_28

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-7226.json"