Lucene search

K
cvelistMitreCVELIST:CVE-2017-14529
HistoryOct 03, 2022 - 4:23 p.m.

CVE-2017-14529

2022-10-0316:23:40
mitre
www.cve.org
1
cve-2017-14529
bfd library
libbfd
gnu binutils 2.29
denial of service
heap-based buffer over-read
application crash
crafted pe file
bfd_getl16 function

6 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

52.4%

The pe_print_idata function in peXXigen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, mishandles HintName vector entries, which allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted PE file, related to the bfd_getl16 function.

6 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

52.4%