~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to active/CVE-2017-14333

  • Committer: Leonidas S. Barbosa
  • Date: 2017-09-12 15:36:18 UTC
  • Revision ID: leo.barbosa@canonical.com-20170912153618-giv94yexe1pf0ms7
Process cves run: triaged 9 CVEs, 64 Ignored, 7 Packages

Packages with new cves:
  binutils(1) gdm3(1) graphicsmagick(1) imagemagick(3) nagios3(1)
  tcpreplay(1) wordpress-shibboleth(1)

Show diffs side-by-side

added added

removed removed

Lines of Context:
 
1
Candidate: CVE-2017-14333
 
2
PublicDate: 2017-09-12
 
3
References:
 
4
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14333
 
5
 https://sourceware.org/bugzilla/show_bug.cgi?id=21990
 
6
Description:
 
7
 The process_version_sections function in readelf.c in GNU Binutils 2.29
 
8
 allows attackers to cause a denial of service (Integer Overflow, and hang
 
9
 because of a time-consuming loop) or possibly have unspecified other impact
 
10
 via a crafted binary file with invalid values of ent.vn_next, during
 
11
 "readelf -a" execution.
 
12
Ubuntu-Description:
 
13
Notes:
 
14
 leosilva> code in precise and trusty are quite different, needs backport
 
15
Bugs:
 
16
Priority: medium
 
17
Discovered-by:
 
18
Assigned-to:
 
19
 
 
20
Patches_binutils:
 
21
 patch: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=452bf675ea772002aa86fb1d28f3474da70ee1de
 
22
upstream_binutils: needs-triage
 
23
precise/esm_binutils: needed
 
24
trusty_binutils: needed
 
25
vivid/ubuntu-core_binutils: DNE
 
26
xenial_binutils: needed
 
27
zesty_binutils: needed
 
28
devel_binutils: needed