CVE-2017-13710 is a denial-of-service vulnerability affecting the GNU Binutils library (libbfd) versions 2.29 and earlier. It allows remote attackers to crash an application via a crafted binary file containing a malformed group section, leading to a NULL pointer dereference in the setup_group function. With a CVSS score of 7.5 (High), this vulnerability can be exploited remotely with low attack complexity and no user interaction, resulting in high availability impact. There is currently no known public exploit code (Metasploit, Nuclei, ExploitDB), and it has not been added to the CISA KEV catalog, nor is there significant community discussion or media coverage surrounding it.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.29CPE matchmatch criteria | cpe:2.3:a:gnu:binutils:2.29:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.