Fedora Account System
Red Hat Associate
Red Hat Customer
coffgen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, does not validate the symbol count, which allows remote attackers to cause a denial of service (integer overflow and application crash, or excessive memory allocation) or possibly have unspecified other impact via a crafted PE file. Upstream issue: https://sourceware.org/bugzilla/show_bug.cgi?id=22385 Upstream patches: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=6cee897971d4d7cd37d2a686bb6d2aa3e759c8ca
Created binutils tracking bugs for this issue: Affects: fedora-all [bug 1499311] Created mingw-binutils tracking bugs for this issue: Affects: epel-all [bug 1499310]