High severity7.8NVD Advisory· Published Oct 29, 2017· Updated May 13, 2026
CVE-2017-15996
CVE-2017-15996
Description
elfcomm.c in readelf in GNU Binutils 2.29 allows remote attackers to cause a denial of service (excessive memory allocation) or possibly have unspecified other impact via a crafted ELF file that triggers a "buffer overflow on fuzzed archive header," related to an uninitialized variable, an improper conditional jump, and the get_archive_member_name, process_archive_index_and_symbols, and setup_archive functions.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- sourceware.org/bugzilla/show_bug.cginvdIssue TrackingPatchThird Party Advisory
- www.securityfocus.com/bid/101608nvdThird Party AdvisoryVDB Entry
- security.gentoo.org/glsa/201801-01nvd
News mentions
0No linked articles in our index yet.