CVE-2020-16599: Null Pointer Dereference
A Null Pointer Dereference vulnerability exists in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.34, in bfdelfgetsymbolversionstring, as demonstrated in nm-new, that can cause a denial of service via a crafted file.
External References:
https://sourceware.org/bugzilla/showbug.cgi?id=25842 https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=8d55d10ac0d112c586eaceb92e75bd9b80aadcc4
Other sources
A Null Pointer Dereference vulnerability exists in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.35, in bfdelfgetsymbolversionstring, as demonstrated in nm-new, that can cause a denial of service via a crafted file.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-16599?
CVE-2020-16599 is a Null Pointer Dereference vulnerability in the Binary File Descriptor (BFD) library, as distributed in GNU Binutils 2.35.
How does CVE-2020-16599 affect the affected software?
CVE-2020-16599 can cause a denial of service in the affected software via a crafted file.
What is the severity of CVE-2020-16599?
CVE-2020-16599 has a severity rating of medium with a CVSS score of 5.5.
How can I fix CVE-2020-16599?
To fix CVE-2020-16599, update GNU Binutils to version 2.35 or apply the appropriate patch provided by Red Hat.
Where can I find more information about CVE-2020-16599?
You can find more information about CVE-2020-16599 on the following sources: [sourceware.org/bugzilla/show_bug.cgi?id=25842](sourceware.org/bugzilla/show_bug.cgi?id=25842), [sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=8d55d10ac0d112c586eaceb92e75bd9b80aadcc4](sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=8d55d10ac0d112c586eaceb92e75bd9b80aadcc4), [bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1906763](bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=1906763).