Resource exhaustion in Binutils - CVE-2019-9073
Published: August 1, 2019 / Updated: January 21, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to an error when allocating memory in _bfd_elf_slurp_version_tables() function in elf.c within the libbfd library, distributed in GNU Binutils. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
Gentoo Linux
sys-devel/binutils
How to mitigate CVE-2019-9073
sys-devel/binutils - update to 2.35.2