CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 5.5. It may be remotely exploitable. It may lead to a denial-of-service condition.
CVE
CVE-2017-17080
Severity
MEDIUM
CVSS
5.5
EPSS
1.29%
Original NVD Description
elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, does not validate sizes of core notes, which allows remote attackers to cause a denial of service (bfd_getl32 heap-based buffer over-read and application crash) via a crafted object file, related to elfcore_grok_netbsd_procinfo, elfcore_grok_openbsd_procinfo, and elfcore_grok_nto_status.
Related CVEs
Other vulnerabilities affecting the same vendor(s)