A flaw was found in the ignoresectionsym function in elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, does not validate the outputsection pointer in the case of a symtab entry with a "SECTION" type that has a "0" value, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file, as demonstrated by objcopy.
References: https://sourceware.org/bugzilla/showbug.cgi?id=23113
Patch: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=db0c309f4011ca94a4abc8458e27f3734dab92ac
A flaw was found in the bfdXXbfdcopyprivatebfddatacommon function in peXXigen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, processes a negative Data Directory size with an unbounded loop that increases the value of (externalIMAGEDEBUGDIRECTORY) edd so that the address exceeds its own memory region, resulting in an out-of-bounds memory write, as demonstrated by objcopy copying private info with bfdpex64bfdcopyprivatebfddatacommon in pex64igen.c.
References: https://sourceware.org/bugzilla/showbug.cgi?id=23110
Patch: https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=aa4a8c2a2a67545e90c877162c53cc9de42dc8b4
The swapstdrelocin function in aoutx.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows attackers to cause a denial of service (aout32swapstdrelocout NULL pointer dereference and application crash) via a crafted ELF file, as demonstrated by objcopy.
Upstream issue:
https://sourceware.org/bugzilla/showbug.cgi?id=22887
Upstream patches:
https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=116acb2c268c89c89186673a7c92620d21825b25