Back

MEDIUM

binutils: out of bounds memory write in peXXigen.c files

Published Apr 29, 2018

Description

The _bfd_XX_bfd_copy_private_bfd_data_common function in peXXigen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, processes a negative Data Directory size with an unbounded loop that increases the value of (external_IMAGE_DEBUG_DIRECTORY) *edd so that the address exceeds its own memory region, resulting in an out-of-bounds memory write, as demonstrated by objcopy copying private info with _bfd_pex64_bfd_copy_private_bfd_data_common in pex64igen.c.

Affected products

Remediation

No remediation recorded yet.

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 29, 2018
Updated Aug 5, 2024
Reserved Apr 29, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Apr 24, 2018