Loading HuntDB...

GHSA-x3hp-v34p-5x6h

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

coffgen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, does not validate the symbol count, which allows remote attackers to cause a denial of service (integer overflow and application crash, or excessive memory allocation) or possibly have unspecified other impact via a crafted PE file.

Related CVEs

Key Information

GHSA ID
GHSA-x3hp-v34p-5x6h
Published
May 14, 2022 1:56 AM
Last Modified
April 20, 2025 3:48 AM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: August 31, 2025 6:33 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.