CVE-2017-14333

Severity CVSS v4.0:
Pending analysis
Type:
CWE-190 Integer Overflow or Wraparound
Publication date:
12/09/2017
Last modified:
20/04/2025

Description

The process_version_sections function in readelf.c in GNU Binutils 2.29 allows attackers to cause a denial of service (Integer Overflow, and hang because of a time-consuming loop) or possibly have unspecified other impact via a crafted binary file with invalid values of ent.vn_next, during "readelf -a" execution.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gnu:binutils:2.29:*:*:*:*:*:*:*