system/binutils: multiple vulnerabilities
Bugzilla ID | 212 |
Alias(es) | CVE-2019-17450, CVE-2019-17451 |
Reporter | Max Rees (sroracle) |
Assignee | Max Rees (sroracle) |
Reported | 2019-10-16 16:38:57 -0500 |
Modified | 2019-10-16 20:14:17 -0500 |
Status | RESOLVED FIXED |
Version | 1.0-BETA3 |
Hardware | Adélie Linux / All |
Importance | --- / normal |
Description
CVE-2019-17450: https://nvd.nist.gov/vuln/detail/CVE-2019-17450
find_abstract_instance in dwarf2.c in the Binary File Descriptor (BFD)
library (aka libbfd), as distributed in GNU Binutils 2.32, allows
remote attackers to cause a denial of service (infinite recursion and
application crash) via a crafted ELF file.
CVE-2019-17451: https://nvd.nist.gov/vuln/detail/CVE-2019-17451
An issue was discovered in the Binary File Descriptor (BFD) library
(aka libbfd), as distributed in GNU Binutils 2.32. It is an integer
overflow leading to a SEGV in _bfd_dwarf2_find_nearest_line in
dwarf2.c, as demonstrated by nm.