Lucene search

K
osvGoogleOSV:CVE-2018-7208
HistoryFeb 18, 2018 - 4:29 a.m.

CVE-2018-7208

2018-02-1804:29:00
Google
osv.dev
2

7.9 High

AI Score

Confidence

High

0.012 Low

EPSS

Percentile

85.4%

In the coff_pointerize_aux function in coffgen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, an index is not validated, which allows remote attackers to cause a denial of service (segmentation fault) or possibly have unspecified other impact via a crafted file, as demonstrated by objcopy of a COFF object.