First published: Tue Aug 22 2023(Updated: )
An issue was discovered in binutils libbfd.c 2.36 relating to the auxiliary symbol data allows attackers to read or write to system memory or cause a denial of service.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNU Binutils | =2.36 | |
debian/binutils | <=2.35.2-2 | 2.40-2 2.43.1-5 |
https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=4fd8d5856435ff84de1f181381fc51754285af6f
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-19726 is a vulnerability discovered in binutils libbfd.c 2.36 that allows attackers to read or write to system memory or cause a denial of service.
CVE-2020-19726 has a severity score of 8.8 (high).
The following software versions are affected by CVE-2020-19726: GNU Binutils 2.36, binutils packages 2.31.1-16 to 2.35.2-2 for Debian, binutils package 2.36 for Ubuntu, binutils package 2.30-21ubuntu1~18.04.9+ for Ubuntu (bionic), binutils package 2.24-5ubuntu14.2+ for Ubuntu (trusty), and binutils package 2.26.1-1ubuntu1~16.04.8+ for Ubuntu (xenial).
To fix CVE-2020-19726, you should update your affected software to the latest version provided by your vendor.
You can find more information about CVE-2020-19726 on the following references: [Bugzilla #26240](https://sourceware.org/bugzilla/show_bug.cgi?id=26240) and [Bugzilla #26241](https://sourceware.org/bugzilla/show_bug.cgi?id=26241).