9.1
CVSSv3

CVE-2017-6969

Published: 17/03/2017 Updated: 03/10/2019
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.1 | Impact Score: 5.2 | Exploitability Score: 3.9
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:P

Vulnerability Summary

readelf in GNU Binutils 2.28 is vulnerable to a heap-based buffer over-read while processing corrupt RL78 binaries. The vulnerability can trigger program crashes. It may lead to an information leak as well.

Vulnerable Product Search on Vulmon Subscribe to Product

gnu binutils 2.28

Vendor Advisories

Debian Bug report logs - #858324 binutils: CVE-2017-7210 Package: src:binutils; Maintainer for src:binutils is Matthias Klose <doko@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 21 Mar 2017 09:57:05 UTC Severity: important Tags: fixed-upstream, patch, security, upstream Found in versi ...
Debian Bug report logs - #858263 binutils: CVE-2017-6966 Package: binutils; Maintainer for binutils is Matthias Klose <doko@debianorg>; Source for binutils is src:binutils (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Mon, 20 Mar 2017 13:03:01 UTC Severity: important Tags: fixed-upstr ...
Debian Bug report logs - #858264 binutils: CVE-2017-6965 Package: binutils; Maintainer for binutils is Matthias Klose <doko@debianorg>; Source for binutils is src:binutils (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Mon, 20 Mar 2017 13:03:01 UTC Severity: important Tags: fixed-upstr ...
Debian Bug report logs - #858323 binutils: CVE-2017-7209 Package: src:binutils; Maintainer for src:binutils is Matthias Klose <doko@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 21 Mar 2017 09:57:02 UTC Severity: important Tags: fixed-upstream, patch, security, upstream Found in versi ...
Debian Bug report logs - #858256 binutils: CVE-2017-6969 Package: binutils; Maintainer for binutils is Matthias Klose <doko@debianorg>; Source for binutils is src:binutils (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Mon, 20 Mar 2017 13:03:01 UTC Severity: important Tags: fixed-upstr ...
readelf in GNU Binutils 228 is vulnerable to a heap-based buffer over-read while processing corrupt RL78 binaries The vulnerability can trigger program crashes It may lead to an information leak as well ...
It has been discovered that readelf in GNU Binutils 228 is vulnerable to a heap-based buffer over-read while processing corrupt RL78 binaries ...