dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, mishandles NULL files in a .debug_line file table, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted ELF file, related to concat_filename. NOTE: this issue is caused by an incomplete fix for CVE-2017-15023.
The product dereferences a pointer that it expects to be valid but is NULL.
| Name | Vendor | Start Version | End Version | 
|---|---|---|---|
| Binutils | Gnu | 2.29 (including) | 2.29 (including) | 
| Binutils | Ubuntu | artful | * | 
| Binutils | Ubuntu | esm-infra-legacy/trusty | * | 
| Binutils | Ubuntu | esm-infra/xenial | * | 
| Binutils | Ubuntu | precise/esm | * | 
| Binutils | Ubuntu | trusty | * | 
| Binutils | Ubuntu | trusty/esm | * | 
| Binutils | Ubuntu | upstream | * | 
| Binutils | Ubuntu | xenial | * | 
| Binutils | Ubuntu | zesty | * |