CVE-2017-8398 is an invalid read vulnerability in GNU Binutils 2.28's dwarf.c, affecting tools like objdump and readelf when processing corrupt binaries. Rated 7.5 HIGH on CVSS, it poses a remote, low-complexity denial-of-service risk, as it can crash analysis programs without requiring user interaction or privileges. There is no evidence of active exploitation, public exploit code, or significant community discussion, suggesting a low current threat level.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.28CPE matchmatch criteria | cpe:2.3:a:gnu:binutils:2.28:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.