CVE-2017-17080 is a denial-of-service vulnerability affecting GNU Binutils 2.29.1, specifically in the Binary File Descriptor (BFD) library's elf.c. It stems from a lack of validation for core note sizes, allowing a remote attacker to trigger a heap-based buffer over-read and application crash via a crafted object file. Rated Medium (CVSS 5.5), this vulnerability requires user interaction (UI:R) and local access (AV:L) to exploit, leading to high availability impact (A:H) but no confidentiality or integrity loss. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage, suggesting low current threat activity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.29.1CPE matchmatch criteria | cpe:2.3:a:gnu:binutils:2.29.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.