---
cve: "CVE-2017-15996"
severity: "LOW"
cvss: 3.1
epss: "2.4%"
vendor: "n/a"
kev: false
exploited: false
published: "2017-10-29 17:29:00"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-18T08:38:07+02:00"
---

# CVE-2017-15996

> 3.1 LOW

## Beschreibung

elfcomm.c in readelf in GNU Binutils 2.29 allows remote attackers to cause a denial of service (excessive memory allocation) or possibly have unspecified other impact via a crafted ELF file that triggers a "buffer overflow on fuzzed archive header," related to an uninitialized variable, an improper conditional jump, and the get_archive_member_name, process_archive_index_and_symbols, and setup_archive functions.

## Referenzen

- <http://www.securityfocus.com/bid/101608>
- <https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git%3Bh=d91f0b20e561e326ee91a09a76206257bde8438b>
- <https://security.gentoo.org/glsa/201801-01>
- <https://sourceware.org/bugzilla/show_bug.cgi?id=22361>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2017-15996) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
