The print_symbol_for_build_attribute function in readelf.c in GNU Binutils 2017-04-12 allows remote attackers to cause a denial of service (invalid read and SEGV) via a crafted ELF file.
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/98587 | vdb entry |
https://blogs.gentoo.org/ago/2017/05/12/binutils-multiple-crashes/ | vdb entry third party advisory patch |