[Bug binutils/32030] New: Algorithmic complexity vulnerability (CWE-407) in BFD

2024-07-27 Thread nhweideman at gmail dot com
Component: binutils Assignee: unassigned at sourceware dot org Reporter: nhweideman at gmail dot com Target Milestone: --- Note: This vulnerability is reported publicly by request of a Debian team member. # Overview We discovered an algorithmic complexity vulnerability (CWE

[Bug binutils/32030] Algorithmic complexity vulnerability (CWE-407) in BFD

2024-08-03 Thread nhweideman at gmail dot com
https://sourceware.org/bugzilla/show_bug.cgi?id=32030 --- Comment #2 from Nicolaas Weideman --- I agree that DoS is probably not the main concern here because, as you mentioned, services analyzing untrusted code should have reasonable timeouts to prevent DoS. That being said, "timeout" is clearl