An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. a heap-based buffer over-read in bfd_getl32 in libbfd.c allows an attacker to cause a denial of service through a crafted PE file. This vulnerability can be triggered by the executable objdump. References: https://sourceware.org/bugzilla/show_bug.cgi?id=23685 Upstream Patch: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=cf93e9c2cf8f8b2566f8fc86e961592b51b5980d
Created binutils tracking bugs for this issue: Affects: fedora-all [bug 1632924] Created mingw-binutils tracking bugs for this issue: Affects: epel-all [bug 1632923] Affects: fedora-all [bug 1632927]