Lucene search

K
osvGoogleOSV:CVE-2017-14974
HistoryOct 02, 2017 - 1:29 a.m.

CVE-2017-14974

2017-10-0201:29:00
Google
osv.dev
8

6.5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

31.0%

The *_get_synthetic_symtab functions in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, mishandle the failure of a certain canonicalization step, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted ELF file, related to elf32-i386.c and elf64-x86-64.c.

6.5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

31.0%