VYPR

BFD library

by GNU

CVEs (2)

  • CVE-2017-8421MedMay 2, 2017
    risk 0.36cvss 5.5epss 0.00

    The function coff_set_alignment_hook in coffcode.h in Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has a memory leak vulnerability which can cause memory exhaustion in objdump via a crafted PE file. Additional validation in…

  • CVE-2018-7208Feb 18, 2018
    risk 0.00cvss epss 0.00

    In the coff_pointerize_aux function in coffgen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, an index is not validated, which allows remote attackers to cause a denial of service (segmentation fault) or possibly have unspecified…