Fedora Account System
Red Hat Associate
Red Hat Customer
elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, does not validate sizes of core notes, which allows remote attackers to cause a denial of service (bfd_getl32 heap-based buffer over-read and application crash) via a crafted object file, related to elfcore_grok_netbsd_procinfo, elfcore_grok_openbsd_procinfo, and elfcore_grok_nto_status. Upstream issue: https://sourceware.org/bugzilla/show_bug.cgi?id=22421 Upstream patches: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=80a0437873045cc08753fcac4af154e2931a99fd
Created binutils tracking bugs for this issue: Affects: fedora-all [bug 1499311]
Created mingw-binutils tracking bugs for this issue: Affects: epel-all [bug 1499310]