#VU18958 Out-of-bounds read in Binutils - CVE-2019-12972
Published: July 2, 2019 / Updated: March 23, 2022
Binutils
GNU
Description
The vulnerability allows an attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to heap-based buffer over-read condition within the "_bfd_doprnt" function in the "bfd.c" file in the Binary File Descriptor (BFD) library. A local attacker can pass a malformed ELF binary to the affected application and perform a denial of service attack.