The srec_scan function in bfd/srec.c in libdbfd in GNU binutils before 2.25 allows remote attackers to cause a denial of service (out-of-bounds read) via a small S-record.
{ "ubuntu_priority": "medium", "availability": "No subscription required", "binaries": [ { "binary_name": "binutils", "binary_version": "2.24-5ubuntu3.1" }, { "binary_name": "binutils-dev", "binary_version": "2.24-5ubuntu3.1" }, { "binary_name": "binutils-doc", "binary_version": "2.24-5ubuntu3.1" }, { "binary_name": "binutils-multiarch", "binary_version": "2.24-5ubuntu3.1" }, { "binary_name": "binutils-multiarch-dev", "binary_version": "2.24-5ubuntu3.1" }, { "binary_name": "binutils-source", "binary_version": "2.24-5ubuntu3.1" }, { "binary_name": "binutils-static", "binary_version": "2.24-5ubuntu3.1" }, { "binary_name": "binutils-static-udeb", "binary_version": "2.24-5ubuntu3.1" } ] }