First published: Wed Dec 09 2020(Updated: )
A Null Pointer Dereference vulnerability exists in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.34, in _bfd_elf_get_symbol_version_string, as demonstrated in nm-new, that can cause a denial of service via a crafted file. External References: <a href="https://sourceware.org/bugzilla/show_bug.cgi?id=25842">https://sourceware.org/bugzilla/show_bug.cgi?id=25842</a> <a href="https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=8d55d10ac0d112c586eaceb92e75bd9b80aadcc4">https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=8d55d10ac0d112c586eaceb92e75bd9b80aadcc4</a>
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNU Binutils | =2.35 | |
Netapp Cloud Backup | ||
Netapp Hci Management Node | ||
NetApp ONTAP Select Deploy administration utility | ||
Netapp Solidfire | ||
redhat/binutils | <2.35 | 2.35 |
https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=8d55d10ac0d112c586eaceb92e75bd9b80aadcc4
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-16599 is a Null Pointer Dereference vulnerability in the Binary File Descriptor (BFD) library, as distributed in GNU Binutils 2.35.
CVE-2020-16599 can cause a denial of service in the affected software via a crafted file.
CVE-2020-16599 has a severity rating of medium with a CVSS score of 5.5.
To fix CVE-2020-16599, update GNU Binutils to version 2.35 or apply the appropriate patch provided by Red Hat.
You can find more information about CVE-2020-16599 on the following sources: [sourceware.org/bugzilla/show_bug.cgi?id=25842](sourceware.org/bugzilla/show_bug.cgi?id=25842), [sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=8d55d10ac0d112c586eaceb92e75bd9b80aadcc4](sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=8d55d10ac0d112c586eaceb92e75bd9b80aadcc4), [bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1906763](bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1906763).