readelf in GNU Binutils 2.28 is vulnerable to a heap-based buffer over-read while processing corrupt RL78 binaries. The vulnerability can trigger program crashes. It may lead to an information leak as well.
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://sourceware.org/bugzilla/show_bug.cgi?id=21156 | issue tracking exploit vdb entry third party advisory |
https://security.gentoo.org/glsa/201709-02 | vendor advisory |
http://www.securityfocus.com/bid/97065 | vdb entry |